π Hello cybersecurity enthusiasts (and those pretending to be π),
Welcome to the July edition of The Tyrex Files! Summer is here, the beaches are calling… and apparently, so are the attackers β who decided that walking into offices in person with USB drives was a perfectly reasonable thing to do in 2026. (Spoiler: it works. Keep reading.)
This month, we’ve got an FBI warning that sounds like a heist movie, an entire army compromised by counterfeit thumb drives, a gadget that hunts evil cables, and a double dose of Christophe’s geeking wisdom. Grab your coffee (or your rosΓ©, it’s July, we don’t judge), and let’s dive in!
Let’s keep those USBs clean!
Christophe & GΓ©rard.
π¨ Top Cybersecurity Stories: USB Threats and More
- FBI Warning: Hackers Are Now Showing Up IN PERSON With USB Drives π΅οΈ
You read that right. The FBI issued an alert about the Silent Ransom Group (SRG), an extortion gang active since 2022 that targets US law firms β and has now escalated to physically walking into offices. Posing as IT support, their operatives claim they need to “image a workstation” or “run a backup,” convince employees to let them plug in their own USB drive, and walk out with sensitive client files. No ransomware, no encryption β pure extortion via a data leak site.
Spring 2026 marked the first documented in-person theft attempts, and victims include legal giant Jones Day. The FBI’s advice? Verify credentials and restrict USB ports.
Ours? The network perimeter means nothing when the threat walks through the front door with a smile and a lanyard.
π Sources: FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data and the original report from the FBI.

- Japan’s Military Ran on Malware-Infected Counterfeit USB Drives… For a Year π―π΅
Japan’s Ground Self-Defense Force discovered that counterfeit USB drives loaded with China-linked malware sat inside its military computers for nearly a year before detection. It all started when someone noticed a PC running slowly after inserting a drive at the Middle Army HQ near Osaka.
The investigation found 6 infected drives and 50+ exposed systems β nearly half connected to classified command-and-control networks. The kicker: these fake drives (advertising 1 TB, actually holding ~240 GB on cheap microSD cards) arrived through earthquake disaster-relief operations, and the endpoint security software had excluded them from scans. The malware executed automatically on insertion.
If a modern military can be compromised for a year by knock-off thumb drives, what about your factory floor?
π Sources: Japanβs army used USB drives with Chinese malware for a year

and the original article in Nikkei Asia
- WireBadger: The Gadget That Sniffs Out Evil Cables π
Berkeley Varitronics Systems (led by cybersecurity veteran Scott Schober) launched WireBadger, a self-contained tester that detects malicious components hidden inside USB and Lightning cables β before they compromise your devices. It spots the suspicious current draws and rogue Wi-Fi/Bluetooth signals given off by keyloggers and implants hiding in seemingly innocent cables, across USB-A, B, C, Mini, Micro and Lightning.
Built for pentesters and red teams, it exists because modern weaponized cables carry embedded microcontrollers that attack at the protocol level β completely invisible to antivirus.
When someone builds a dedicated machine just to check cables, you know the “everything USB is a potential weapon” era is officially here. (More on this in Christophe’s corner below. π)
π Sources: WireBadger Malicious Cable Detector For Penetration Testers And Red Teams
π€ Christophe’s Cybersecurity Geeking Corner: Double Feature Edition!
This month, you get TWO words for the price of one. (Inflation? Never heard of her. π)
Word #1: The O.MG Cable π
It looks exactly like your regular charging cable. Same size, same weight, it even charges your phone like a champ. Except this one hides a tiny microcontroller with built-in Wi-Fi. Once plugged in, it can impersonate a keyboard, “type” malicious commands at lightning speed, log your keystrokes, and send everything to an attacker sitting comfortably… up to a mile away. Your antivirus? It sees nothing β as far as your computer knows, that’s just you typing. The scary part: these cables sell online for less than a decent restaurant dinner. Remember our story above about WireBadger? Now you know why someone built a machine just to detect evil cables. The lesson: in 2026, even your cable needs a background check.

Word #2: The Air Gap ποΈ
An “air-gapped” network is a network physically isolated from the Internet β no cables in, no Wi-Fi out. On paper, it’s unhackable: military systems, nuclear plants, factory floors love it. But here’s the catch: an air gap only stops what travels through wires. It does nothing against what walks through the door in someone’s pocket.
π A single USB stick can jump the gap β That’s exactly how counterfeit USB drives sat inside Japan’s military, and how counterfeit USB drives sat inside Japan’s military networks for a year (see this month’s top stories β yes, everything connects!). The lesson: an air gap without strict control of removable media isn’t a moat. It’s a welcome mat.
And if you want both problems handled at once β a station that checks everything that’s about to cross your air gap β well, you know where to find us. π

π GΓ©rard’s Top Cybersecurity Resources: What the Big Ransomware Numbers Don’t Tell You
Black Kite’s 2026 Ransomware Report is out β and I read it so you don’t have to. (You’re welcome. β)
π By the Numbers:
- 7,551 ransomware victims tracked between April 2025 and March 2026 β a 24.9% jump year-over-year
- 146 active ransomware groups as of June 2026, with the Qilin gang exploding by +443%
- The US still takes the biggest hit (49.3% of victims), but Europe is catching up fast: Germany +48%, Italy +96%, France ~+50%
- And the headline that matters most to us: Manufacturing is the #1 targeted industry for the 4th year in a row, with 1,660 victims (22% of the total)
π€ GΓ©rard’s Take: Here’s what jumped out at me β and what the report doesn’t spell out.
Manufacturing has been ransomware’s favorite punching bag for four straight years. Now ask yourself: which industry relies the most on USB drives to update air-gapped machines, transfer files to OT systems, and let third-party technicians service production lines?

Exactly the same one. π That’s no coincidence β every USB stick walking onto a factory floor is a potential first domino in the next ransomware headline. The Honeywell data we’ve shared before already showed USB as the top attack vector in industrial environments; Black Kite’s numbers show you what’s waiting at the end of that chain.
And one more connection worth making: remember this month’s top story about the Silent Ransom Group physically walking into offices with USB drives? That’s the extortion economy Black Kite is measuring β 146 groups strong and growing. The macro numbers and the micro tactics tell the same story: the door your firewall can’t close is the USB port. π
π Sources: The full report is free and interactive β no download, no email wall: Black Kite 2026 Ransomware Report
π§ Bonus β The 3 Podcasts OT Security Pros Actually Listen To:
We ran an audience analysis on US IT & OT security professionals working in manufacturing and critical infrastructure. Here’s what’s actually in their earbuds (data-backed, not just our opinion!):
- Hack the Plant β Bryson Bort explores how connecting critical infrastructure to the Internet leaves us vulnerable. 4.8 stars, essential listening.
- (CS)Β²AI Podcast Show β Derek Harp interviews the people securing control systems, backed by a 34,000-member professional community.
- @BEERISAC β Anton Shipulin’s curated playlist of the best OT/ICS security episodes from around the world. One subscription, all the gems.
π Cybersecurity Experts to Follow
This month, we did something different: instead of giving you OUR favorite experts, we analyzed audience data from US industrial & OT security professionals to find out who they actually follow and listen to. Here’s the data-backed podium:
- Bryson Bort πΊπΈ β (LinkedIn) Founder of SCYTHE and co-founder of the ICS Village at DEF CON, host of the Hack the Plant podcast. THE voice of critical infrastructure security in the US.
- Dale Peterson πΊπΈ β (LinkedIn) Founder of the S4 conference, host of Unsolicited Response, and a pioneering figure in ICS/SCADA security for over two decades.
π€ USBs Gone Wild: “The Perfect Gift”
This month’s flash drive fiasco β well, this time it’s not even a flash drive. That’s the whole point.
The Setup: Three weeks after a major industrial trade show, the operations director of a mid-sized precision manufacturing company receives a beautiful gift box in the mail. Inside: premium chocolates, a leather notebook, and an elegant USB-C charging cable with a matching power bank β his company’s logo laser-engraved on it. The card reads: “Great meeting you at the show. Looking forward to working together β The BusinessPartners Team.” He vaguely remembers talking to dozens of people at the booth. Classy touch, he thinks. The chocolates are gone by 3pm. The cable earns a permanent spot on his desk. π«
The Trojan Cable: Except this cable charges his phone and his attacker’s ambitions. Hidden inside the connector β a space smaller than a fingernail β sits a microcontroller with built-in Wi-Fi. The kind of implant we talked about in this month’s Geeking Corner (see? Everything connects π). Plugged into his workstation, the cable identifies itself as a keyboard. No file to scan, no executable to flag β his antivirus sees ten fingers typing. Late one evening, the “keyboard” quietly types: a few commands, a hidden payload download, a discreet backdoor. Total execution time: under 15 seconds.
The Silent Harvest: For weeks, the attackers explore. They map the network, collect credentials, and locate what they came for: the engineering file server, and the workstations used to prepare firmware updates for the production line β updates that travel to air-gapped machines by USB stick. The isolated OT network everyone considered untouchable suddenly has a bridge: an infected update drive, prepared on a compromised workstation, walked across the air gap by a trusted employee. (Our second Geeking Corner word in action. We told you it was a double feature for a reason. ποΈ)
The Discovery: The intrusion is caught during a routine security assessment when an analyst notices an unknown Wi-Fi signal broadcasting… from a desk. Not from a router. From a cable. The forensics bill, the production audit, and the client notifications cost the company more than a decade’s worth of legitimate charging cables. The gift box’s sender? A company that never existed.
How Tyrex Would Have Changed the Ending:
- Every incoming USB device gets checked β not just storage. A Tyrex station with behavioral analysis detects firmware-level threats: a “cable” that announces itself as a keyboard raises an immediate red flag. π©
- The update drives crossing the air gap get decontaminated at a kiosk before touching any OT system β the bridge gets a checkpoint.
- The security team gets alerted the moment a suspicious device shows up, turning a months-long breach into a five-minute incident report.
The Lesson: Everyone knows not to plug in a USB stick found in a parking lot. But a gift? With your own logo on it? Social engineering doesn’t pick locks β it gets invited in. In 2026, “don’t trust unknown USB devices” includes the ones wrapped in ribbon. π
(Yes, this story is fictional β but every technique in it is real, from the FBI’s warnings about in-person USB attacks to the counterfeit drives found in Japan’s military networks. See this month’s top stories. We don’t make this stuff up… reality does.)
π Meanwhile, at the Tyrex HQ…
A few things happened on our side of the USB port lately β and for once, we’re actually telling you about them. (More on that irony below. π)
π¨π¦ Tyrex is now officially Canadian too, eh! On July 9th, we announced the opening of TYREX Canada, headquartered in Sherbrooke, Quebec, alongside a reinforced strategic partnership with SECLAB, the French experts in critical systems protection. Xavier Facelina, SECLAB’s co-founder, is taking the helm of our Canadian operations, with Sherbrooke serving as an R&D hub surrounded by universities and research centers. North America, we’re not just visiting anymore β we’re moving in. (Full announcement)

π³οΈ ICYMI: we hit the high seas. A while back, we exhibited at Seatrade Cruise Global in Miami, the world’s biggest cruise industry gathering. Our takeaway from talking to the industry: modern ships are floating data centers, their OT networks can’t be virtualized, and maritime still ranks last among transport industries for cybersecurity maturity. In other words: our favorite kind of challenge. (Our full debrief)
β Take Action!
Want to learn more about how Tyrex can protect your organization from USB threats β from counterfeit drives to weaponized cables?
- Schedule a free consultation with GΓ©rard β 30 minutes, no sales pitch, just straight answers to your USB security questions.
- Christophe to the rescue for your technical deep-dives.
- Discover our USB decontamination stations and how they secure industrial, maritime, pharma and defense environments π Tyrex-cyber.com
See you next month β and until then, think twice before plugging in that gift. π
Powered by Tyrex USA