Case Library / Physical Social Engineering (Tailgating & Baiting) / FIN7 BadUSB "Best Buy" Gift Card Mailings via USPS

FIN7 BadUSB "Best Buy" Gift Card Mailings via USPS

FIN7 (Carbanak) mailed USPS packages disguised as Best Buy gift-card rewards containing BadUSB hardware implants to HR, IT, and executive staff at US retail, restaurant, and hotel companies, aiming to trigger automatic malware installation the moment a curious employee plugged the device in.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Starting by at least December 2019 and continuing through 2020 (with related mailings resurfacing in 2021), the FIN7 cybercrime group (also known as Carbanak) mailed USPS packages to HR, IT, and executive staff at US retail, restaurant, and hotel companies. The packages impersonated Best Buy and included a letter claiming the recipient had a gift card (commonly cited as $50) or a physical gift such as a teddy bear, paired with a USB device the letter said could be used to redeem or view eligible purchases. The USB was actually a BadUSB-style hardware keystroke-injection device (an Arduino Leonardo/ATMEGA32U4-class board, marked "HW-374") that, when plugged into a computer, automatically typed commands to launch an obfuscated PowerShell chain, fetch a second-stage script from an attacker-controlled domain, and install a JavaScript backdoor performing system reconnaissance and command-and-control beaconing (behavior consistent with FIN7's GRIFFON malware). Trustwave SpiderLabs obtained and reverse-engineered one such package, received by a US hospitality-sector target in mid-February 2020, after the intended victim recognized the mailing as suspicious and did not connect the device. The FBI issued a nationwide FLASH alert (MI-000120-MW) on March 26, 2020, warning the retail, restaurant, and hotel industries about the campaign, and issued an updated FLASH (MU-000160-MW) on January 6, 2022 describing continued and evolved mailings (different lures such as HHS/Amazon impersonation, LilyGO-branded USBs, decorative gift boxes) against a wider set of sectors, with the stated intent of gaining network access, moving laterally, and deploying ransomware (e.g., BlackMatter, REvil).

How the Attack Worked

The attack combined a physical social-engineering lure with a hardware exploit. Victims received a USPS package impersonating Best Buy: an official-looking letter stating the recipient had won/was owed a gift (in some versions a $50 Best Buy gift card, in others a teddy bear or gift card), accompanied by a USB drive. The letter framed the USB as containing a list of items the "gift card" could be redeemed for, encouraging the recipient to plug it in to see. The USB was not a storage device but a BadUSB-style hardware implant (Trustwave identified it as an Arduino Leonardo-class board with an ATMEGA32U4 microcontroller, PCB marked "HW-374") that emulates a USB keyboard (HID device). Once inserted, it auto-typed a keystroke injection sequence that opened a command line and ran an obfuscated PowerShell command with no user interaction beyond plugging it in. That command pulled a second-stage script from an attacker domain (milkmovemoney[.]com/st/mi.ini), copied wscript.exe to %AppData%MicrosoftWindowswipre.exe, dropped an obfuscated JScript file (prada.txt), and executed a JavaScript backdoor. The backdoor registered the host with a command-and-control server and harvested extensive system reconnaissance data (username, hostname, domain, OS build/version, user privileges, running processes, installed Office/Adobe products, hardware/memory info, timezone), consistent with the GRIFFON malware/backdoor associated with FIN7. Packages were mailed to HR, IT, and executive-management staff at retail, restaurant, and hotel businesses, exploiting the trust and low suspicion generated by an ordinary-looking package from a familiar consumer brand.

The Lure & the Tell

The Tell: an unsolicited package arriving via USPS, "from" a well-known retailer (Best Buy) the recipient likely never contacted, containing a USB drive plus a gift/reward pretext (gift card, teddy bear) with a letter urging the recipient to plug the USB in to "see what it can buy," a classic too-good-to-be-true reciprocity hook combined with curiosity bait, sent to a business address (HR/IT/executive) rather than a home, which is itself atypical for genuine retail promotions. The device also physically resembled repurposed low-cost hobbyist hardware (Arduino Leonardo/HW-374 board) rather than an actual USB flash drive. In the documented case the recipient caught the incongruity (unsolicited "gift" tied to a USB device mailed to a business) and referred it to security instead of plugging it in: that referral was the save.

Outcome

The Trustwave-analyzed February 2020 package was detected and stopped before any device was connected: the recipient at the hospitality-sector victim organization recognized the mailing as suspicious and handed it to security/IT rather than plugging it in, allowing Trustwave SpiderLabs to safely disassemble and analyze the hardware and payload. No confirmed compromise, data breach, or financial loss has been publicly reported from this specific intercepted package. The FBI issued a nationwide FLASH alert (MI-000120-MW, March 26, 2020) warning retail, restaurant, and hospitality businesses about the campaign, and updated it in a second FLASH (MU-000160-MW, January 6, 2022) after similar mailings resurfaced through 2020 and again in August/November 2021 against additional sectors (transportation, insurance, defense), using varied lures (HHS or Amazon impersonation, decorative gift boxes, counterfeit gift cards, LilyGO-branded USB devices). The 2022 update noted FIN7's broader intrusions (via this and other initial-access vectors) aimed at deploying ransomware such as BlackMatter and REvil, though that ransomware outcome was not tied specifically to the intercepted Best Buy-lure package.

Why It Matters

This case is one of the best-documented real-world examples of a nation-scale criminal group operationalizing physical mail as an initial-access vector, bridging "digital" cybercrime with old-fashioned baiting: instead of a phishing email, the lure was a tangible package that exploited reciprocity (an unexpected gift), curiosity, and trust in a household retail brand, sent specifically to roles (HR, IT, executives) who routinely receive vendor mail and may be less trained to distrust physical hardware than a suspicious email attachment. It demonstrates that security awareness training must extend beyond email/phishing to cover unsolicited physical devices and mail-borne lures, and that basic USB device-control policies (disabling autorun, restricting unknown HID/storage devices) are a necessary technical backstop even when human vigilance succeeds, as it did in the documented case. Because FIN7/Carbanak is one of the most financially damaging cybercrime groups on record (linked to hundreds of millions of dollars in fraud across other campaigns), the campaign also illustrates how a top-tier criminal organization will invest in low-tech, high-trust delivery mechanisms when they offer a reliable path around email security controls.

Defenses

FBI FLASH alert (MI-000120-MW, updated as MU-000160-MW) urged organizations to: train staff never to connect unknown/unsolicited USB devices to corporate systems; establish and enforce USB device policies (disable autorun, restrict USB ports via endpoint policy/Group Policy, use USB device control/allow-listing software); route any suspicious mailed hardware to security/IT for analysis rather than testing it; treat unsolicited gifts, gift cards, or promotional mailings addressed to HR, IT, or executives as a social-engineering red flag; monitor for the specific IOCs published (domains, hashes, PowerShell/JScript patterns); and report incidents to the FBI/IC3. The documented 2020 case shows the control that actually worked: an alert employee recognized the lure as suspicious and did not plug the device in, instead escalating it to security, which allowed Trustwave to analyze it safely.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and targeting: FIN7 is documented (per Trustwave SpiderLabs and the FBI FLASH alerts) as mailing packages specifically to HR, IT, and executive-management staff at retail, restaurant, and hotel businesses, roles likely chosen because they routinely receive vendor mail and promotional gifts without automatic suspicion. Compiling business mailing addresses and role information likely relied on commercially available business-contact data rather than any technical intrusion.
Countering Stage 1: Business-role targeting data (who holds HR, IT, or executive titles at a given company) is hard to fully suppress since it is often published for legitimate contact purposes; the realistic control is training those specific roles to treat unsolicited gifts and promotional mail as a social-engineering vector, handled at Stages 4 and 5 below.
2
Lure and hardware preparation: The group sourced low-cost, commercially available BadUSB-style HID-emulator hardware (Arduino Leonardo/ATMEGA32U4-class boards marked "HW-374") and prepared brand-impersonation lure letters (a Best Buy gift-card reward, with later variants using HHS, Amazon, and other pretexts) plus supporting props such as gift boxes or a teddy bear, consistent with FBI reporting on the campaign's evolution.
Countering Stage 2: BadUSB hardware is cheap, commercially available, and legally sold for legitimate penetration testing, so purchase cannot be blocked; the effective control is preventing untrusted HID devices from executing commands once received, covered at Stage 5.
3
Payload staging: FIN7 stood up attacker-controlled infrastructure (domains such as milkmovemoney[.]com) to host the second-stage PowerShell script and command-and-control functions, and programmed the USB microcontroller to auto-inject an obfuscated keystroke sequence on connection, per Trustwave's reverse-engineering of the device.
Countering Stage 3: Attacker domain registration and hosting is best disrupted after the fact through threat-intel-driven domain and IOC blocklisting and takedown requests once identified, as the FBI did by publishing the campaign's IOCs in its FLASH alerts, though this is reactive rather than preventive.
4
Delivery via USPS: The BadUSB device and lure letter were mailed as an ordinary-looking package to the target's business address via the US Postal Service, exploiting the comparatively low security scrutiny applied to physical mail compared with email attachments, as described in the FBI FLASH alerts.
Countering Stage 4: Mailroom and physical-security procedures that treat unsolicited packages containing gift cards, promotional USB devices, or unexpected gifts addressed to HR, IT, or executives as a red flag, escalating to security rather than routing directly to the named recipient.
5
Execution via HID keystroke injection: When the recipient plugged the USB device into a computer, it auto-typed a keystroke sequence that opened the Windows Run dialog and ran an obfuscated PowerShell command, with no further user interaction required, as documented by Trustwave and the FBI.
Countering Stage 5: Employee security-awareness training never to connect unknown or unsolicited USB devices to corporate systems, combined with technical USB device-control policies (disabling autorun, restricting or allow-listing USB HID devices via endpoint policy or Group Policy); this is the control that actually worked in the documented Trustwave case.
6
Backdoor installation and reconnaissance: The PowerShell chain fetched a second-stage script, dropped an obfuscated JScript payload, and installed a JavaScript backdoor (consistent with FIN7's GRIFFON malware) that registered the host with a command-and-control server and collected system reconnaissance data.
Countering Stage 6: Endpoint detection and response tooling plus PowerShell and script-execution restrictions (such as constrained-language mode, AMSI, and blocking unnecessary wscript.exe/JScript execution paths) to catch obfuscated payload chains even if a device is connected, alongside monitoring for the specific published IOCs (domains, hashes).
7
Objective completion: lateral movement and ransomware deployment (broader campaign objective, not confirmed for this intercepted package): Per the FBI's 2022 FLASH update, FIN7 used successful initial footholds to move laterally, escalate to administrative privileges, and deploy tools such as Cobalt Strike, Carbanak, DICELOADER, and ultimately ransomware (e.g., BlackMatter, REvil) for financial gain, though this final stage was not observed in the documented, intercepted Best Buy-lure package itself.
Countering Stage 7: Network segmentation, least-privilege administrative access, and ransomware-specific controls (offline/immutable backups, monitoring for lateral-movement tooling) to contain damage if initial access is achieved, consistent with the FBI's broader guidance on FIN7 intrusions.
Quick Facts
Victim
Unnamed US hospitality-sector organization analyzed by Trustwave SpiderLabs (package intercepted, February 2020); broader campaign per FBI FLASH targeted unnamed retail, restaurant, and hotel businesses nationwide, primarily HR, IT, and executive-management staff
Location
United States (nationwide campaign targeting US retail, restaurant, and hotel/hospitality businesses; Trustwave's analyzed package was received by a US hospitality-sector organization)
Date
2020-02 (package received by Trustwave-analyzed victim mid-February 2020); FBI FLASH alert issued 2020-03-26 (MI-000120-MW); follow-on FBI update 2022-01-06 (MU-000160-MW)
Impact
None confirmed for the documented 2020 Trustwave/FBI case; the recipient did not connect the device, so no compromise, data loss, or ransom payment resulted from this specific intercepted package. No public reporting ties a dollar loss or confirmed breach to this particular mailing. (Later FBI reporting says FIN7's broader post-access objective in related campaigns was ransomware deployment, e.g., BlackMatter/REvil, but that outcome was not documented as resulting from this intercepted USB package.)
Status
Confirmed
Case Type
Real-World Incident
Sector
Defense & Aerospace, Hospitality, Gaming & Travel, Retail & E-commerce
Threat Actor
Organized Crime
Related

Related Cases

Yujing Zhang Mar-a-Lago Intrusion

A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…

Incident 2019Read →

Rapid7 'Blank Badge' Physical Penetration Test: Tailgating, Door-Reciprocity, and a Fake New-Employee Help-Desk Pretext

A Rapid7 penetration tester tailgated into a client's building using door-holding reciprocity and a cloned-looking badge, rode an elevator up…

Incident 2018Read →

Doorstep Dispensaree: Unsecured Patient Records Found in a Pharmacy's Back Yard Trigger the ICO's First GDPR Fine (2019)

An MHRA search warrant unrelated to data protection stumbled on an estimated ~500,000 (later found to be far fewer) care-home…

Incident 2018Read →