FIN7 (Carbanak) mailed USPS packages disguised as Best Buy gift-card rewards containing BadUSB hardware implants to HR, IT, and executive staff at US retail, restaurant, and hotel companies, aiming to trigger automatic malware installation the moment a curious employee plugged the device in.
Reviewed by the Social Engineering Examples team.
Starting by at least December 2019 and continuing through 2020 (with related mailings resurfacing in 2021), the FIN7 cybercrime group (also known as Carbanak) mailed USPS packages to HR, IT, and executive staff at US retail, restaurant, and hotel companies. The packages impersonated Best Buy and included a letter claiming the recipient had a gift card (commonly cited as $50) or a physical gift such as a teddy bear, paired with a USB device the letter said could be used to redeem or view eligible purchases. The USB was actually a BadUSB-style hardware keystroke-injection device (an Arduino Leonardo/ATMEGA32U4-class board, marked "HW-374") that, when plugged into a computer, automatically typed commands to launch an obfuscated PowerShell chain, fetch a second-stage script from an attacker-controlled domain, and install a JavaScript backdoor performing system reconnaissance and command-and-control beaconing (behavior consistent with FIN7's GRIFFON malware). Trustwave SpiderLabs obtained and reverse-engineered one such package, received by a US hospitality-sector target in mid-February 2020, after the intended victim recognized the mailing as suspicious and did not connect the device. The FBI issued a nationwide FLASH alert (MI-000120-MW) on March 26, 2020, warning the retail, restaurant, and hotel industries about the campaign, and issued an updated FLASH (MU-000160-MW) on January 6, 2022 describing continued and evolved mailings (different lures such as HHS/Amazon impersonation, LilyGO-branded USBs, decorative gift boxes) against a wider set of sectors, with the stated intent of gaining network access, moving laterally, and deploying ransomware (e.g., BlackMatter, REvil).
The attack combined a physical social-engineering lure with a hardware exploit. Victims received a USPS package impersonating Best Buy: an official-looking letter stating the recipient had won/was owed a gift (in some versions a $50 Best Buy gift card, in others a teddy bear or gift card), accompanied by a USB drive. The letter framed the USB as containing a list of items the "gift card" could be redeemed for, encouraging the recipient to plug it in to see. The USB was not a storage device but a BadUSB-style hardware implant (Trustwave identified it as an Arduino Leonardo-class board with an ATMEGA32U4 microcontroller, PCB marked "HW-374") that emulates a USB keyboard (HID device). Once inserted, it auto-typed a keystroke injection sequence that opened a command line and ran an obfuscated PowerShell command with no user interaction beyond plugging it in. That command pulled a second-stage script from an attacker domain (milkmovemoney[.]com/st/mi.ini), copied wscript.exe to %AppData%MicrosoftWindowswipre.exe, dropped an obfuscated JScript file (prada.txt), and executed a JavaScript backdoor. The backdoor registered the host with a command-and-control server and harvested extensive system reconnaissance data (username, hostname, domain, OS build/version, user privileges, running processes, installed Office/Adobe products, hardware/memory info, timezone), consistent with the GRIFFON malware/backdoor associated with FIN7. Packages were mailed to HR, IT, and executive-management staff at retail, restaurant, and hotel businesses, exploiting the trust and low suspicion generated by an ordinary-looking package from a familiar consumer brand.
The Tell: an unsolicited package arriving via USPS, "from" a well-known retailer (Best Buy) the recipient likely never contacted, containing a USB drive plus a gift/reward pretext (gift card, teddy bear) with a letter urging the recipient to plug the USB in to "see what it can buy," a classic too-good-to-be-true reciprocity hook combined with curiosity bait, sent to a business address (HR/IT/executive) rather than a home, which is itself atypical for genuine retail promotions. The device also physically resembled repurposed low-cost hobbyist hardware (Arduino Leonardo/HW-374 board) rather than an actual USB flash drive. In the documented case the recipient caught the incongruity (unsolicited "gift" tied to a USB device mailed to a business) and referred it to security instead of plugging it in: that referral was the save.
The Trustwave-analyzed February 2020 package was detected and stopped before any device was connected: the recipient at the hospitality-sector victim organization recognized the mailing as suspicious and handed it to security/IT rather than plugging it in, allowing Trustwave SpiderLabs to safely disassemble and analyze the hardware and payload. No confirmed compromise, data breach, or financial loss has been publicly reported from this specific intercepted package. The FBI issued a nationwide FLASH alert (MI-000120-MW, March 26, 2020) warning retail, restaurant, and hospitality businesses about the campaign, and updated it in a second FLASH (MU-000160-MW, January 6, 2022) after similar mailings resurfaced through 2020 and again in August/November 2021 against additional sectors (transportation, insurance, defense), using varied lures (HHS or Amazon impersonation, decorative gift boxes, counterfeit gift cards, LilyGO-branded USB devices). The 2022 update noted FIN7's broader intrusions (via this and other initial-access vectors) aimed at deploying ransomware such as BlackMatter and REvil, though that ransomware outcome was not tied specifically to the intercepted Best Buy-lure package.
This case is one of the best-documented real-world examples of a nation-scale criminal group operationalizing physical mail as an initial-access vector, bridging "digital" cybercrime with old-fashioned baiting: instead of a phishing email, the lure was a tangible package that exploited reciprocity (an unexpected gift), curiosity, and trust in a household retail brand, sent specifically to roles (HR, IT, executives) who routinely receive vendor mail and may be less trained to distrust physical hardware than a suspicious email attachment. It demonstrates that security awareness training must extend beyond email/phishing to cover unsolicited physical devices and mail-borne lures, and that basic USB device-control policies (disabling autorun, restricting unknown HID/storage devices) are a necessary technical backstop even when human vigilance succeeds, as it did in the documented case. Because FIN7/Carbanak is one of the most financially damaging cybercrime groups on record (linked to hundreds of millions of dollars in fraud across other campaigns), the campaign also illustrates how a top-tier criminal organization will invest in low-tech, high-trust delivery mechanisms when they offer a reliable path around email security controls.
FBI FLASH alert (MI-000120-MW, updated as MU-000160-MW) urged organizations to: train staff never to connect unknown/unsolicited USB devices to corporate systems; establish and enforce USB device policies (disable autorun, restrict USB ports via endpoint policy/Group Policy, use USB device control/allow-listing software); route any suspicious mailed hardware to security/IT for analysis rather than testing it; treat unsolicited gifts, gift cards, or promotional mailings addressed to HR, IT, or executives as a social-engineering red flag; monitor for the specific IOCs published (domains, hashes, PowerShell/JScript patterns); and report incidents to the FBI/IC3. The documented 2020 case shows the control that actually worked: an alert employee recognized the lure as suspicious and did not plug the device in, instead escalating it to security, which allowed Trustwave to analyze it safely.
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
A Rapid7 penetration tester tailgated into a client's building using door-holding reciprocity and a cloned-looking badge, rode an elevator up…
An MHRA search warrant unrelated to data protection stumbled on an estimated ~500,000 (later found to be far fewer) care-home…