Introduction
PhishPro allows you to run simulated attacks using USB drives. The customer sets up the campaign independently: the platform sends a "malicious" Word file via email to the designated contact, who then loads it onto USB drives and distributes them. The platform then tracks who opens the file.
The CSM should only be involved to review any customization requests, which must be checked and approved.
This feature is available exclusively for organizations that have purchased the "Phish Pro" Add-on and activated the corresponding licenses.
Important note: The "Phish Pro" Add-on must be properly purchased for the organization in question. Activation for testing or trial purposes is not allowed. If you have any doubts or special requirements, contact support before activation.
Enabling the USB Attack
To activate a USB attack, follow these steps:
- Go to the Setup > Phishing section.
- Enable the "Enable USB Attack" option.
Once enabled, the feature will be visible within the "Release Management" section, under "Remediation".
USB attacks can also be carried out on new targets, meaning users who have never received any type of attack before.
Types of USB Attacks
There are two types of USB attacks:
- USB Attack with Macro: In this scenario, when the user inserts the USB drive into their device, opens the file, and enables the macro (using the "Enable Content" option), the hostname and IP address of the machine are recorded. However, macro execution may be blocked by company policies; therefore, you need to check on a case-by-case basis if this attack method is feasible, possibly supporting it with a certified macro.
Important for the macro mode: Company policies often block macro execution. It is the customer's responsibility to check if this mode can be used and to adjust company policies so the macro can run. If macros are blocked, use the mode without macros or a certified macro managed by the customer.
- USB Attack without Macro: In this mode, only a file open event (one click per user) is recorded, without collecting specific details like hostname or IP. This approach provides aggregate data on user interaction with the file.
Sending the Malicious File
To launch the USB attack, simply click "Start" in the "Release Management" section. You will need to choose the template (USB type) to use.
NOTE: You can only select one template per campaign. If you create a new template, it will be available for selection in Phish Pro the day after it is created.
Managing Campaign Duration
In the section dedicated to managing duration, you can enter:
- Campaign Start Date: Indicates the date from which the platform will begin recording interactions with the malicious file. You cannot enter a date in the past.
- Campaign Duration: Defines the period during which events will be recorded. Events that occur before the start date or after the end date will not be considered by the Cyber Guru platform.
- Campaign Start Time: Specifies the exact time when the platform starts recording interactions with the malicious file.
- Email sending duration: this field should be left blank.
Contact Information
Next, you will need to enter the email address of the contact who will receive the email containing the malicious file to be loaded onto the USB drives. You can enter any email address here, even one belonging to a user not registered within the company.
NOTE: The email will be sent to the specified contact the DAY AFTER the campaign is set up in the platform.
The contact will receive an email with the content from the template and the malicious file attached. The message in the template is global.
Every interaction the contact has with the attached file (for example, opening the file or running the macro) will be counted and recorded in the campaign's final report.
NOTE: It's important to remind the contact about the campaign duration and the exact time from which the platform will start recording interactions, so they can properly organize the USB distribution of the malicious file.
Customizing the ATTACHMENT
Customizing the attachment is the customer's responsibility. The standard file sent includes instructions for customizing the file.
Reporting
At the end of the campaign you can download a report that shows:
- Phished IP: Public IP
- Host Name of the machine of the user who opened the file and enabled macro execution
- Host IP: Local IP of the device where macro execution was enabled
Every interaction the contact has with the attached file (for example, opening the file or running the macro) will be counted and recorded in the campaign's final report.
For USB without macro templates, the report only records the click associated with the Phished IP (Public IP).