Ship USB Malware: How Do Ships Get Infected Through USB?

aritime vessels rely on USB ports to transfer data to sensitive shipboard systems with intermittent network connectivity. The crew uses flash drives to upload charts and cargo data, and maintenance crews often use them to extract service logs and transfer diagnostic packages between shore offices and onboard systems.

Every time a USB device that has not been scanned and verified clear of malware connects, ships are at risk of a malware infection. Maritime infrastructure is particularly vulnerable because control‑adjacent systems often use older operating systems that are not compatible with modern endpoint protection and vendor‑controlled updates.

How Malware Moves From Shore to Shipboard Systems

Maritime cybersecurity systems are designed to protect vessels from a range of threats, but USB-borne malware can easily slip past firewalls and other network-based defenses.

A crew member or vendor plugs a USB drive into a bridge workstation or a technician connects their thumb drive to equipment in the engine control room. If the drive contains malware, that endpoint becomes the first point of infection. Modern malware can quickly propagate across sensitive systems, including ECDIS systems and other operational infrastructure.

Crews may notice immediately as OT systems begin to malfunction, or the malware may remain dormant as it waits for the system to be connected to a wider network, at which point it can infect further systems or exfiltrate sensitive data.

Three Ship USB Malware Incidents That Put Ships and Passengers at Risk

A USB Chart Update Infects Navigation Systems

In one vessel incident, a crew member brought a USB stick on board to print paperwork. The device introduced malware into ship computers. Later, another crew member used USB media to update the vessel’s electronic charts before sailing, transferring the malware into the ship’s ECDIS system and delaying departure from the port.

A Service Provider USB Infects Power Management

Another case involved an infected shipboard power management system. Investigators found evidence of malware infection across all servers linked to the equipment. The malware had been present for 875 days, and the infection was eventually traced back to a service provider, who had introduced the malware with a USB flash drive during a routine software installation.

Espionage Spyware Attacks Cargo Ships

In 2024, reporting based on ESET findings identified Mustang Panda-linked malware inside cargo shipping companies in Norway, Greece, and the Netherlands. The Korplug malware is a remote access Trojan associated with state-level espionage. It establishes persistent, covert control so attackers can harvest system information and open remote command-line sessions on infected machines. It typically enters networks through phishing emails or compromised USB devices

What IMO 2021 Expects Operators to Control

IMO 2021 is the common name for the cyber-risk deadline set by Resolution MSC.428(98), which required companies to address cyber risk within the ship’s safety management system under the ISM Code. Compliant maritime operators introduce removable media controls with clear procedures, assigned roles, and evidence that crews follow them.

The IMO guidelines align with the NIST Cybersecurity Framework. Under its Protect function, operators are expected to apply safeguards that reduce the chance of unauthorized removable media reaching ship systems. IMO does not prescribe a particular technology. It expects operators to manage the risk, and in serious cases, weak cyber-risk management can lead flag-state or port-state control to issue or record a deficiency.

Learn more about IMO 2021 and USB cybersecurity.

How USB Decontamination Reduces Maritime Malware Risk

Ship owners may consider blocking USB ports and banning removable devices, but removable media bans are not viable for most maritime operators. To secure infrastructure, they need an easy‑to‑deploy, easy‑to‑use security gateway that scans USB devices, identifies malware and other threats, and eliminates or quarantines them.

TYREX Decontamination Stations are purpose-built for deployment into operational environments. Crew and maintenance teams can insert a wide range of USB devices and other removable media. The station scans the devices with multiple antimalware engines, as well as static and optional dynamic analysis, to identify threats such as malware, ransomware, code vulnerabilities, and firmware‑level BadUSB threats.

Decontamination stations work alongside existing security systems and can integrate with them to export scan events via Syslog API. Multiple stations can be managed via the TYREX Management Server, which handles centralized administration, reporting, and updates.

Maritime organizations and ship owners can choose from a variety of decontamination station form factors depending on the environment, including:

  • TYREX Mobile: Ruggedized tablet for onboard checks, pier-side maintenance, and mobile teams that scan media away from a fixed station.
  • TYREX Satellite: Compact wall-mount or desktop station for ships, submarines, bridge areas, and small technical spaces.
  • TYREX Console: Desktop station for shore offices, vessel operations centers, and controlled access points where staff process removable media.
  • TYREX Totem: Floor-standing kiosk for port facilities, reception areas, and high-traffic locations where visitors or contractors bring media.

Contact a TYREX specialist to discuss where decontamination stations fit into your maritime USB security workflow

How strong are your removable media defenses?

USB devices can bypass controls designed to monitor network traffic. Take the 8-question USB Security Assessment to identify potential gaps and receive an instant risk profile with practical next steps.

Sign up for the TYREX newsletter for expert analysis and guidance from TYREX USB security experts Gerard Varjacques and Christophe Bourel.