Follow Us

IBM red-faced after handing out USB drives stuffed with malware

Security conference delegates get more than they bargained for

You might get more than you bargained for if you attend a security conference. IBM shocked delegates at the Australian AusCERT conference in Queensland by handing out USB sticks infected with malware.

The company was forced to write to delegates apologising for its error. "At the AusCERT conference this week, you may have collected a complimentary USB key from the IBM booth. Unfortunately we have discovered that some of these USB keys contained malware and we suspect that all USB keys may be affected."

It was actually worse than IBM intimated. To make it doubly embarrassing, according to security company Sophos, the company included two examples of malware: W32/LibHack-A. and W32/Agent-FWF.

Sophos's senior technology consultant, Graham Cluley had a guess how the error occurred. "My guess is that they didn't check the USB sticks before handing them out. Maybe they out-sourced the creation of the USB content to a third party, and they weren't careful enough. After all, if an infected PC was used to create the "image" of the USB drive then it would have been easy for that disk image to be infected and copied onto every USB stick they handed out."

IBM certainly couldn't say that it had been caught up by new malware, Sophos has been detecting W32/Agent-FWF since June 2007.

Cluley said that users should be suspicious of all USB drives – even those handed out at security conferences. "Users should always be cautious about USB sticks, as they are a common carrier of malware. The trick is to disable autorun/autoplay on your computers, and use an up-to-date anti-virus that checks every file accessed in case it contains a virus infection.

"Businesses may also want to put in place technology that controls the use of USB ports (and what can be plugged into them). This not only helps protect against USB-borne malware, but also data loss."






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Business continuity and disaster recovery for SMBs

Business continuity (BC) and disaster recovery (DR) are major issues for all businesses, with...

Download Whitepaper

How to get your business ready for the 2012 Olympics

IT Manager: "I'm working on contingency plans to ensure that we can keep the business running...

Download Whitepaper

10 things you have to do today to protect your business in 2012

The next twelve months will be like a fair ground ride: rotation, uncertainty and mild...

Download Whitepaper

Data protection strategies in the age of the iPad

In today’s target-rich environment, CISOs must focus on defending the content of files and...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards Winners 2011


Learn who the winners of this year's Techworld Awards are. Video footage coming soon...

Find out more
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

Site Map

* *