Browse Definitions :
Definition

USB Killer

A USB Killer is USB drive that has been modified to deliver an electrical surge that can damage or destroy hardware when the altered thumb drive is inserted into a computer's USB port.The modified drive essentially commands the computer's on-board capacitors to rapidly charge and discharge repeatedly. If left alone, the repeated overcharging will overload the USB port and physically destroy the computer's electrical system.

Essentially, a USB Killer works by delivering 210-220 volts to an interface that is designed for 5 volts. The overpowered-surge can damage or destroy not only ports, but also attached hardware. The concept behind USB Killer is similar to that of Ethernet Killer, a modified power cord that does much the same thing.

USB Killer is sold commercially under the name USB Kill. The original concept behind the device was allegedly to help hardware manufacturers and network administrators determine how well a digital device could withstand power surges and electrostatic discharge (ESD). Since its invention, however, this type of altered thumb drive has not been used for penetration testing by any major company -- it has proved popular with cybercriminals, however. 

The concept of a USB Killer is credited to a Russian computer researcher known as Dark purple. In the United States, USB Killer was infamously used in the wild by a student at the College of Saint Rose in upstate New York. The student, who used his iPhone to record himself using USB Killer, destroyed over 60 college computers and was sentenced in 2019 to one year in federal prison. 

To avoid being harmed by a rogue USB Killer, security experts recommend that network administrators and end users take the following steps:

  • Apply firmware updates as soon as they become available.
  • Refrain from using USB drives of unknown origin.
  • Cap USB ports on mission-critical devices. 

This was last updated in June 2019

Continue Reading About USB Killer

Networking
  • Telnet

    Telnet is a network protocol used to virtually access a computer and provide a two-way, collaborative and text-based ...

  • big-endian and little-endian

    The term endianness describes the order in which computer memory stores a sequence of bytes.

  • Address Resolution Protocol (ARP)

    Address Resolution Protocol (ARP) is a protocol that maps dynamic IP addresses to permanent physical machine addresses in a local...

Security
  • Mitre ATT&CK framework

    The Mitre ATT&CK (pronounced miter attack) framework is a free, globally accessible knowledge base that describes the latest ...

  • timing attack

    A timing attack is a type of side-channel attack that exploits the amount of time a computer process runs to gain knowledge about...

  • privileged identity management (PIM)

    Privileged identity management (PIM) is the monitoring and protection of superuser accounts that hold expanded access to an ...

CIO
HRSoftware
  • employee resource group (ERG)

    An employee resource group is a workplace club or more formally realized affinity group organized around a shared interest or ...

  • employee training and development

    Employee training and development is a set of activities and programs designed to enhance the knowledge, skills and abilities of ...

  • employee sentiment analysis

    Employee sentiment analysis is the use of natural language processing and other AI techniques to automatically analyze employee ...

Customer Experience
  • customer profiling

    Customer profiling is the detailed and systematic process of constructing a clear portrait of a company's ideal customer by ...

  • customer insight (consumer insight)

    Customer insight, also known as consumer insight, is the understanding and interpretation of customer data, behaviors and ...

  • buyer persona

    A buyer persona is a composite representation of a specific type of customer in a market segment.

Close