USBs are back: Rare, advanced threat campaign targets users

Kaspersky
Short Url
Updated 21 July 2021
Follow

USBs are back: Rare, advanced threat campaign targets users

  • The Kaspersky Managed Detection and Response service can help identify and stop attacks in their early stages, before the attackers achieve their goals

Kaspersky experts have uncovered a rare, wide-scale advanced persistent threat (APT) campaign against users that was first detected in Southeast Asia. Kaspersky identified approximately 1,500 victims, some of which were government entities. Initial infection occurs via spear-phishing emails containing a malicious Word document; once downloaded on one system, the malware can then spread to other hosts through removable USB drives.
APT campaigns are, by nature, highly targeted. Often, no more than a few dozen users are targeted, often with surgical-like precision. However, recently, Kaspersky uncovered a rare, widespread threat campaign with a rarely used, yet still a movie-like attack vector. Once downloaded on a system, the malware attempts to infect other hosts by spreading through removable USB drives. If a drive is found, the malware creates hidden directories on the drive, where it then moves all of the victim’s files, along with the malicious executables.
This cluster of activity — dubbed LuminousMoth — has been conducting cyber-espionage attacks against government entities since at least October 2020. While initially focusing their attention on Myanmar, the attackers have since shifted their focus to the Philippines. The attackers typically gain an initial foothold in the system through a spear-phishing email with a Dropbox download link. Once clicked, this link downloads a RAR archive disguised as a Word document that contains the malicious payload.

HIGHLIGHT

Kaspersky experts attribute the cyber-espionage attacks to the HoneyMyte threat group, a well-known, long-standing, Chinese-speaking threat actor.

Kaspersky experts attribute LuminousMoth to the HoneyMyte threat group, a well-known, long-standing, Chinese-speaking threat actor, with medium to high confidence. HoneyMyte is primarily interested in gathering geopolitical and economic intelligence in Asia and Africa.
“This new cluster of activity might once again point to a trend we’ve been witnessing over the course of this year: Chinese-speaking threat actors retooling and producing new and unknown malware implants,” said Mark Lechtik, senior security researcher with the Global Research and Analysis Team (GReAT).
To stay safe from advanced threat campaigns like LuminousMoth, Kaspersky experts recommend:
• Providing your staff with basic cybersecurity hygiene training, as many targeted attacks start with phishing or other social engineering techniques.
• Carrying out a cybersecurity audit of your networks and remediating any weaknesses discovered in the perimeter or inside the network.
• nstalling anti-APT and EDR solutions, enabling threat discovery and detection, investigation and timely remediation of incidents capabilities.
All of the above is available within the Kaspersky Expert Security framework.
That along with proper endpoint protection, dedicated services can help against high-profile attacks. The Kaspersky Managed Detection and Response service can help identify and stop attacks in their early stages, before the attackers achieve their goals.


Saudi Awwal Bank becomes first Middle East bank to earn 7-star CinOrg innovation accreditation

Saeed Assiri, chief innovation banking officer at SAB
Updated 05 March 2026
Follow

Saudi Awwal Bank becomes first Middle East bank to earn 7-star CinOrg innovation accreditation

Saudi Awwal Bank has become the first bank in the Middle East to receive a 7‑star Certified Innovative Organization rating from the Global Innovation Institute, the highest recognition awarded by the institute.

The accreditation marks a significant step in SAB’s innovation strategy and follows an innovation maturity assessment conducted by the institute in December 2025. The review, which built on an earlier assessment in December 2023, raised the bank’s maturity level from “Champion” to “Leader.” The new rating reflects SAB’s institutionalized approach to innovation, its enterprise-wide impact and its ability to consistently deliver measurable results.

With the 7‑star rating, SAB becomes the first bank in the region to reach the highest innovation maturity level, strengthening its position as a regional reference point for innovation-led and future-ready banking.

In 2025, the bank opened its flagship Innovation Centre and secured six internationally recognized innovation awards, along with a lab accreditation. The centre has supported SAB’s efforts to accelerate the adoption of advanced technologies, encourage cross-functional collaboration and reinforce its standing as a regional leader in financial innovation.

Saeed Assiri, chief innovation banking officer at SAB, said the recognition reflects years of focused work to build a sustainable innovation ecosystem.

“By investing in SAB’s culture, governance and talent, innovation enables the bank to remain future-ready,” he said. “This milestone reinforces our role in accelerating financial innovation in Saudi Arabia and delivering long-term value for our customers.”

The certification adds to SAB’s broader efforts to strengthen its innovation capabilities as the Kingdom’s banking sector continues to evolve.