Mouse trap: exploiting firmware updates in USB peripherals
Jacob Maskiewicz, B. K. Ellis, James Mouradian, Hovav Shacham · 2014
Although many users are aware of the threats that mal-ware pose, users are unaware that malware can infect peripheral devices. Many embedded devices support firmware update capabilities, yet they do not authenticate such updates; this allows adversaries to infect peripher-als with malicious firmware. We present a case study of the Logitech G600 mouse, demonstrating attacks on networked systems which are also feasible against air-gapped systems. If the target machine is air-gapped, we show that the Logitech G600 has enough space available to host an en-tire malware package inside its firmware. We also wrote a file transfer utility that transfers the malware from the mouse to the target machine. If the target is networked, the mouse can be used as a persistent threat that updates and reinstalls malware as desired. To mitigate these attacks, we implemented signature verification code which is essential to preventing mali-cious firmware from being installed on the mouse. We demonstrate that it is reasonable to include such signa-ture verification code in the bootloader of the mouse. 1