Ultimate magazine theme for WordPress.

Army Free Smartwatch Warning: Don’t Wear These Wearables

Cyber ​​War / Nation-State Attacks, Fraud Management and Cybercrime, Social Engineering

Malware-infected clocks are the new USB stick for social engineers

Mathew J. Schwartz (euroinfosec) •
June 26, 2023

LED D18 smartwatches are sold through online websites (Source: eBay)

Military Members Alert: Received an unsolicited smartwatch in the mail? If so, whatever you do, don’t turn it on and report it to your counterintelligence or security manager.

See also: OnDemand Webinar | Now, learn why CISOs are leveraging these top ASM use cases

This warned the US Army Criminal Investigation Department, saying it had received a number of reports from military personnel claiming that they had been given unsolicited free smartwatches. The devices can do more than just display the time, measure heart rate and count steps.

“When these smartwatches are used, they automatically connect to Wi-Fi and begin connecting to cell phones unsolicited, giving them access to a variety of user data,” the CID’s warning said.

“Malware is also present that accesses both voice and cameras, allowing actors to access conversations and accounts linked to the smartwatches,” the alert reads, adding that the watches may also contain malware capable of harvesting usernames and passwords as well as banking information.

Cybersecurity professionals know that there is no such thing as a free lunch, especially when it comes to digital devices. When you find a “free” USB stick, the question for anyone who has been in the field long enough isn’t whether it contains malware, but how many different types and whether they run automatically when the device is turned on connected to a PC?

Unfortunately for network defenders, people who aren’t paid to be paranoid often fall for the “free stuff” list. In 2011, the US Department of Homeland Security conducted a test to determine how many government employees and private contractors would plug a USB drive they found in their workplace parking lot into their PC.

Bad news, proponents: People who picked up one of the USB devices plugged it in 60% of the time, and even 90% if the device had an official-looking logo or case, Bloomberg reported.

Such concerns are not theoretical, especially when it comes to government networks. In 2008, a malware-infected flash drive was plugged into a US military laptop in the Middle East, causing the malicious code to infiltrate the US Central Command network. The result has been described as “the worst US military computer breach in history.” Officials later said they suspected the attack was carried out from Moscow. The Pentagon’s response to the incident, dubbed Operation Buckshot Yankee and kept secret until 2010, led directly to the creation of the US Cyber ​​Command to better protect government networks.

More than a decade later, attackers continued to use USB thumb drives to inject malware into government and other high-value networks. In January 2022, the FBI issued a rapid alert that companies in the transportation, defense and insurance sectors were being sent boxes containing an alleged Amazon gift card and USB flash drive. The instructions included told recipients to run the executable on the flash drive and said they included important COVID-19 guidance for the U.S. Department of Health and Human Services.

The FBI blamed these attacks on a financially motivated cybercrime group called FIN7, which has been active since 2013. The group has a long history of deploying malware, including malicious code designed to steal payment card details via point-of-sale attacks. In 2020, the group shifted its focus to big game hunting, using ransomware-as-a-service tools like REvil and the group’s own DarkSide, security researchers reported.

Inexpensive attack vectors

Budget smartwatches clearly seem to be the new USB sticks.

For security reasons, the irony is that the Chinese-made smartwatches, sometimes shipped to military personnel as “LED D18 Smart Watches,” retail for around $5 and are likely to cost a lot less in bulk. Anyone who wanted one had to pay little to get one.

It is unclear whether military personnel are directly attacked.

The Army’s warning relates to “brushing,” a type of scam used by some e-commerce website sellers, often based in China, to artificially boost their sales by offering consumers unsolicited — and sometimes counterfeit — products send for verification and counting of items sold as original goods. A study by the British consumer protection agency Which? found in 2021 that 1.1 million households in the UK were victims of brushing their teeth.

US military personnel could simply be among the Americans targeted by the apparent “brushing,” but in reality they are criminals who have loaded malware onto the devices, likely to attempt to steal bank account information. Or they are directly targeted as part of a spy operation. Even if the former is the case, and foreign criminals use malware to obtain sensitive information, the criminals may not hesitate to forward the details to their own intelligence agency.

These watches could be “a valuable collection resource for a foreign intelligence agency,” ReliaQuest CISO Rick Holland told CNN. “Watches then paired with phones could have access to even more data that would be valuable for profiling individual soldiers and their units.”

The message for anyone who receives an unsolicited wearable or other digital device in the mail — or finds one in the parking lot of the agency they work at — remains simple: don’t show it off; They are not good for your health.

Comments are closed.

%d bloggers like this: