-
Language
-
Africa
-
Asia Pacific
-
Europe
-
Latin America
-
Middle East
-
North America
-
- Support
- Contact Us
-
-
Need a Honeywell Account?
Create an AccountAlready have a Honeywell account?
Sign In -
Home My Account Order Management Invoice Management Case Management Saved Carts Address Book Legacy myTransactions Price Agreement Wishlist Advanced Search Preferred Business EntitymyProcess Home My Account Favorites Saved Cart Address Book Order Management Invoice Management Quote History Discount History Service ContractsMy Account My Profile My Orders My Orders Shop My Quotes My Returns Saved Carts Return Requests Invoices My Contracts Case History Work Order History My Subscriptions My Assets Manage Trainings & UsersCurrency:Localize your Content
You can set your preferred currency for this account.
Currency- CHOOSE YOUR CURRENCY
Update Currency
Changing Currency will cause your current cart to be deleted. Click OK to proceed.
To Keep your current cart, click CLOSE and then save your cart before changing currency.
Select AccountSwitching accounts will update the product catalog available to you. When switching accounts, your current cart will not move to the new account you select. Your current cart will be available if you log back into this account again.
Account# Account Name City Zip/Post Code PROCEEDCANCELMy Account
-
You are browsing the product catalog for
You are viewing the overview and resources for
to view parts associated with your account
The Silent Danger of USB-Borne Malware
Highlights from the latest USB Threat Report from Honeywell’s Global Analysis, Research and Defense team
Honeywell’s Global Analysis, Research and Defense (GARD) team has been analyzing USB-borne malware and publishing their findings in an annual report for the past six years. The report is based on telemetry from deployments of Honeywell’s Secure Media Exchange (SMX) product, which is designed to use a variety of methods to enforce access controls on USB media and to prevent access to unwanted files. It could be a simple policy decision – your organization simply doesn’t allow certain files in their facilities – or it could be because a file is infected.
If a file is malicious, Honeywell wants to know more about it. The GARD team is typically focused mainly on two areas: how did it get there, and what is it capable of? But Honeywell wanted to expand the focus, so this year the GARD team did something extra.
Understanding the USB Threat Vector
From years of engagement with customers, it is clear that most active infections found in industrial areas were introduced via USB. Honeywell SMX’s deployment provided a new lens for examining this specific threat vector.
In Honeywell SMX’s first year, a surprising amount of malware detected was spyware, PUAs (potentially unwanted applications), adware and various forms of junkware. Yes, USBs were compromised, but there wasn’t much discernable intent. The malware found was also, for the most part, less dangerous. Still, there were indications that more was going on.
Escalating Risks in Industrial Environments
High-profile malware attributed to large adversarial groups and nation-backed actors were found. Stuxnet, even though already nearly a decade old at that time, popped up. The Mirai botnet was highly prevalent, as was NotPetya. It was only in the second year that things began to get intriguing. Of the malware analyzed – specifically, malware that was detected and blocked while attempting to enter an OT facility – the amount that posed an actual risk to industrial operations effectively doubled.
The next year, it happened again. In 2022 and 2023, the growth continued to slow. Now, that growth seems to be holding steady – albeit at dangerous levels, with 80% of the malware analyzed being capable of causing loss of view or loss of control of an industrial process. The samples now included new variants of just about every prevalent industrial threat of the day, including Trisis.
Dangerous Malware Trends
Year after year, the same findings emerge: malware seems to be targeted; the malware found on USBs seems to be there because it’s intentionally propagating via USB; it can cause LOC; and it seems to be disproportionately slanted toward providing remote access and command-and-control.
This is why the GARD team started tracking a few additional details, and why they looked more closely into specific tactics and techniques.
Modern Cyberattack Techniques
Targeted cyber-physical attacks aren’t about zero-day exploits anymore. They’re about silent residency and “living off the land” techniques – knowing how to use the system to do their dirty work and waiting for the right time to do so.
It’s no surprise that this year Honeywell saw a huge focus on observational tactics (discovery, collection and exfiltration), evasion and persistence. When zooming in on ICS-specific tactics, the team found nothing but execution and escalation tactics, using techniques that leverage the inherent capabilities of the target system.
If you’re interested in reading more about what the Honeywell GARD team discovered this year, check out the 2024 USB Threat Report and see what you can do to better prepare for attacks and threats against your operations.
Copyright © 2026 Honeywell International Inc
Maximum File Size
Maximum Files Exceeded
Due to inactivity you will be logged out in 000 seconds.
Maximum File Size
Maximum Files Exceeded
You cannot access this page as this product is not available in your country.
Maximum File Size
Maximum Files Exceeded
This product is not available in your country.
You cannot access this page as this product is not available in your current country. To view this product, please change your product catalog view.
View product catalog for:
We use cookies and similar tracking online technologies to improve website performance, record website activities, facilitate information sharing on social media and offer advertising tailored to your interest. For more information, see our Cookie Notice and Terms and Conditions. You can also customize your browser’s cookie settings. Please note that if you refuse cookies, it may affect site functionality and performance.