BadUSB

BadUSB refers to a class of security attacks where the internal firmware of a USB device, such as a flash drive, is reprogrammed to make the device present itself as something else to the computer, most commonly a keyboard classified under HID.

Once a computer accepts the device as an innocent looking keyboard, the attack can type commands automatically at high speed, without any file being opened or any obvious malware running, which is what makes BadUSB hard to catch with normal antivirus software that scans files rather than device behaviour.

Because BadUSB exploits the trust built into how USB devices identify themselves, the most effective protection is being cautious about plugging in unknown USB devices from untrusted sources, rather than relying on scanning alone. See our USB security guide for broader precautions.

Matching productUSB flash driveAmazon →