Browse Definitions :
Definition

USB Killer

Contributor(s): Matthew Haughn

A USB Killer is USB drive that has been modified to deliver an electrical surge that can damage or destroy hardware when the altered thumb drive is inserted into a computer's USB port.The modified drive essentially commands the computer's on-board capacitors to rapidly charge and discharge repeatedly. If left alone, the repeated overcharging will overload the USB port and physically destroy the computer's electrical system.

Essentially, a USB Killer works by delivering 210-220 volts to an interface that is designed for 5 volts. The overpowered-surge can damage or destroy not only ports, but also attached hardware. The concept behind USB Killer is similar to that of Ethernet Killer, a modified power cord that does much the same thing.

USB Killer is sold commercially under the name USB Kill. The original concept behind the device was allegedly to help hardware manufacturers and network administrators determine how well a digital device could withstand power surges and electrostatic discharge (ESD). Since its invention, however, this type of altered thumb drive has not been used for penetration testing by any major company -- it has proved popular with cybercriminals, however. 

The concept of a USB Killer is credited to a Russian computer researcher known as Dark purple. In the United States, USB Killer was infamously used in the wild by a student at the College of Saint Rose in upstate New York. The student, who used his iPhone to record himself using USB Killer, destroyed over 60 college computers and was sentenced in 2019 to one year in federal prison. 

To avoid being harmed by a rogue USB Killer, security experts recommend that network administrators and end users take the following steps:

  • Apply firmware updates as soon as they become available.
  • Refrain from using USB drives of unknown origin.
  • Cap USB ports on mission-critical devices. 

This was last updated in June 2019

Continue Reading About USB Killer

Start the conversation

Send me notifications when other members comment.

Please create a username to comment.

-ADS BY GOOGLE

File Extensions and File Formats

Powered by:

SearchCompliance

  • PCI DSS (Payment Card Industry Data Security Standard)

    The Payment Card Industry Data Security Standard (PCI DSS) is a widely accepted set of policies and procedures intended to ...

  • risk management

    Risk management is the process of identifying, assessing and controlling threats to an organization's capital and earnings.

  • compliance framework

    A compliance framework is a structured set of guidelines that details an organization's processes for maintaining accordance with...

SearchSecurity

  • DNS over HTTPS (DoH)

    DNS over HTTPS (DoH) is a relatively new protocol that encrypts domain name system traffic by passing DNS queries through a ...

  • integrated risk management (IRM)

    Integrated risk management (IRM) is an approach to risk management that uses a set of practices and processes to improve an ...

  • MITRE ATT&CK framework

    The MITRE ATT&CK (pronounced 'miter attack') framework is a free, globally accessible service that provides comprehensive and ...

SearchHealthIT

  • telemedicine (telehealth)

    Telemedicine is the remote delivery of healthcare services, such as health assessments or consultations, over the ...

  • Project Nightingale

    Project Nightingale is a controversial partnership between Google and Ascension, the second largest health system in the United ...

  • medical practice management (MPM) software

    Medical practice management (MPM) software is a collection of computerized services used by healthcare professionals and ...

SearchDisasterRecovery

SearchStorage

  • M.2 SSD

    An M.2 SSD is a solid-state drive (SSD) that conforms to a computer industry specification and is used in internally mounted ...

  • kilobyte (KB or Kbyte)

    A kilobyte (KB or Kbyte) is a unit of measurement for computer memory or data storage used by mathematics and computer science ...

  • virtual memory

    Virtual memory is a memory management capability of an operating system (OS) that uses hardware and software to allow a computer ...

Close