Adrian Kingsley-Hughes, a senior contributing editor at ZDNET, once lent a friend what he thought was an ordinary cable. Later that day he got a notification: the cable had captured the login credentials of the computer it was plugged into and sent them to him. It was one of his O.MG test cables, mixed up with the normal ones. He told the story this week in a round-up of cables and dongles that can damage hardware or steal data.
The five he warns about
- USB-A to USB-A cables. USB-A was designed as the end that supplies power, so connecting two hosts can do anything from nothing at all to sparks and smoke. They exist for niche jobs such as KVM switches and flashing firmware.
- “Medusa” multi-head charging cables. Good ones shut down safely if power is connected the wrong way; he has seen plenty of cheap ones simply die.
- The O.MG cable. It looks and behaves like a normal cable but hides a microprocessor and a Wi-Fi chip, so it can inject keystrokes, run scripts and log keys. Some can wipe their payload or self-destruct if discovered.
- USBKill dongles. Built to damage the device they are plugged into with a high-voltage discharge, triggered on insertion, by an app, on a schedule, by radio or with a magnetic ring. In his experience newer hardware resists better than pre-USB-C hardware, but plenty still dies.
- Fake data blockers. A real data blocker passes power but not data, and he carries one when charging from ports he doesn’t control. Some look-alikes carry malicious payloads instead.
The article also covers “widowmaker” male-to-male mains extension cords, which can kill; the US Consumer Product Safety Commission has secured commitments from large marketplaces to delist them. His three rules: don’t plug random cables or dongles into your devices, use a data blocker when travelling, and never use a widowmaker cord.
Where a firewall fits, honestly
A cable like the O.MG works by pretending to be a keyboard. Whatever it types, the Mac treats as if you typed it. No firewall can tell those keystrokes from yours, and FireAI doesn’t claim to. Two things do help against this part: on Mac laptops with Apple silicon, macOS can ask before a new USB accessory is allowed to connect (System Settings › Privacy & Security › Allow accessories to connect; “Ask for new accessories” or stricter), and the Keyboard Setup Assistant that appears when an unknown “keyboard” is plugged in is a warning sign if you didn’t plug in a keyboard. Close it and unplug.
Where FireAI does have a role is what happens next. A cable with its own Wi-Fi chip can send what it captures without touching your network, and FireAI won’t see that. But keystrokes are often used to fetch and start a program, and that program then has to talk to the internet from your Mac. FireAI asks the first time any app wants to connect, shows every destination on the world map, and has a kill switch that refuses new connections in one click.
The other common USB trick is simpler: a stick or drive with a program on it that someone runs. USB Network Protection is built for that case. An app launched from an external or removable drive never gets online silently; in Paranoid and Under attack modes it is denied outright, unless you have explicitly allowed that app. It does not, and cannot, stop a cable that types or a dongle that sends a power surge. Those need the physical habits above.
For more on how these attacks play out, see our guide to the USB drop attack. Download FireAI and try it free for 17 days. FireAI is made by HisnLabs.