Session

YubiWorm: Turning a Trusted YubiKey into a Propagating Worm

Hardware security tokens like YubiKeys are trusted worldwide as a gold standard for authentication. But what happens when trust becomes an attack vector? This talk introduces YubiWorm, a proof-of-concept experiment that transforms a seemingly secure YubiKey into a propagating worm capable of spreading across systems via HID injection and OTP/static password abuse.

We’ll walk through the design, payload delivery mechanism, and propagation strategy, showing how a simple reprogramming of a YubiKey can weaponize it into a stealthy USB-borne worm. Attendees will learn:
• How security tokens interact at the OS level.
• The dual-use potential of HID/OTP features for persistence and propagation.
• Why hardware trust boundaries are fragile without layered defenses.

Jordan Lanham

President, Cyber Saguaros (University of Arizona)

Tucson, Arizona, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top