/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Mandiant details UNC53, a China-backed group that hacked 29+ global orgs since 2022 by tricking staff into using malware-infected USB drives, mostly in Africa

Andy Greenberg / Wired : Mastodon: @GossiTheDog@cyberplace.social . Bluesky: @agreenberg.bsky.social Mastodon: Kevin Beaumont / @GossiTheDog@cyberplace.social : Y'all may remember my #TheWormCircus mega thread here from earlier this year (which sadly got auto deleted as I forgot to favourite it), but Mandiant have noticed it so now pretend to be surprised that USB worms that exfiltrate data are a thing. https://www.wired.com/... Bluesky: Andy Greenberg / @agreenberg.bsky.social : A China-backed spy group breached 29 orgs' networks in 2022-23 using a method you'd expect to find in 2012 or 2008: infected USB drives. https://www.wired.com/... In many cases, malware hit multinationals' Africa-based staff, coming from spots like airport internet cafes.

Wired Andy Greenberg

Context & Ripple Effects

The campaign extends a recurring finding in related coverage: espionage operators can reuse older, removable-media infection paths rather than relying only on internet-facing exploits. Mandiant previously described Turla’s use of decade-old USB-spreading malware, showing that the technique remains operationally useful across state-linked activity.

It also sits alongside reports of China-sponsored intrusions into critical-infrastructure organizations, but this case emphasizes an endpoint and employee-mediated route, with Africa-based personnel disproportionately affected.

First-order effects

  • The more than 29 affected organizations must treat removable media as a potential initial-access route and investigate whether USB-borne malware reached internal systems or enabled data theft.
  • Mandiant’s disclosure gives defenders concrete indicators and a social-engineering pattern to incorporate into endpoint monitoring and employee guidance, especially for personnel handling external drives.

Second-order effects

  • Security teams may tighten USB device controls, scanning, and least-privilege policies, trading some field-work convenience for lower exposure to employee-mediated infections.
  • Attackers that depend on staff inserting compromised media face faster detection once this pattern is operationalized, potentially pushing them toward other endpoint or remote-access entry points.

Third-order effects

  • If state-linked groups continue to pair familiar malware delivery methods with targeted social engineering, security programs will need to treat physical-device hygiene as part of enterprise cyber defense rather than a legacy concern.
  • The case reinforces a broader shift toward defending the human and endpoint perimeter: technical controls alone are less durable when a trusted employee can introduce the initial foothold.

The trend: State-linked cyberespionage is continuing to exploit low-complexity access paths, making endpoint behavior and removable-media controls enduring parts of strategic defense.

Discussion

  • @agreenberg.bsky.social Andy Greenberg on bluesky
    A China-backed spy group breached 29 orgs' networks in 2022-23 using a method you'd expect to find in 2012 or 2008: infected USB drives. https://www.wired.com/... In many cases, malware hit multinationals' Africa-based staff, coming from spots like airport internet cafes.