Mandiant details UNC53, a China-backed group that hacked 29+ global orgs since 2022 by tricking staff into using malware-infected USB drives, mostly in Africa
Andy Greenberg / Wired : Mastodon: @GossiTheDog@cyberplace.social . Bluesky: @agreenberg.bsky.social Mastodon: Kevin Beaumont / @GossiTheDog@cyberplace.social : Y'all may remember my #TheWormCircus mega thread here from earlier this year (which sadly got auto deleted as I forgot to favourite it), but Mandiant have noticed it so now pretend to be surprised that USB worms that exfiltrate data are a thing. https://www.wired.com/... Bluesky: Andy Greenberg / @agreenberg.bsky.social : A China-backed spy group breached 29 orgs' networks in 2022-23 using a method you'd expect to find in 2012 or 2008: infected USB drives. https://www.wired.com/... In many cases, malware hit multinationals' Africa-based staff, coming from spots like airport internet cafes.
Context & Ripple Effects
The campaign extends a recurring finding in related coverage: espionage operators can reuse older, removable-media infection paths rather than relying only on internet-facing exploits. Mandiant previously described Turla’s use of decade-old USB-spreading malware, showing that the technique remains operationally useful across state-linked activity.
It also sits alongside reports of China-sponsored intrusions into critical-infrastructure organizations, but this case emphasizes an endpoint and employee-mediated route, with Africa-based personnel disproportionately affected.
First-order effects
- The more than 29 affected organizations must treat removable media as a potential initial-access route and investigate whether USB-borne malware reached internal systems or enabled data theft.
- Mandiant’s disclosure gives defenders concrete indicators and a social-engineering pattern to incorporate into endpoint monitoring and employee guidance, especially for personnel handling external drives.
Second-order effects
- Security teams may tighten USB device controls, scanning, and least-privilege policies, trading some field-work convenience for lower exposure to employee-mediated infections.
- Attackers that depend on staff inserting compromised media face faster detection once this pattern is operationalized, potentially pushing them toward other endpoint or remote-access entry points.
Third-order effects
- If state-linked groups continue to pair familiar malware delivery methods with targeted social engineering, security programs will need to treat physical-device hygiene as part of enterprise cyber defense rather than a legacy concern.
- The case reinforces a broader shift toward defending the human and endpoint perimeter: technical controls alone are less durable when a trusted employee can introduce the initial foothold.
The trend: State-linked cyberespionage is continuing to exploit low-complexity access paths, making endpoint behavior and removable-media controls enduring parts of strategic defense.