← All terms

Drive-by Download

A drive-by download infects a device through a compromised or malicious web page, with little or no user action beyond visiting the site.

A drive-by download is an infection delivered by a web page rather than an attachment: the victim visits a site — often a legitimate one that has been compromised — and malware is downloaded and executed with little or no further interaction. In the classic form, an exploit kit probes the visitor's browser and plugins for known vulnerabilities and silently installs its payload when it finds one. In the more common modern form, the page uses deception instead of an exploit: a fake browser update, a bogus codec or font error, or a counterfeit CAPTCHA tricks the visitor into approving the download themselves.

How it works

The attacker first needs traffic. They get it by compromising established websites, buying poisoned ads through malvertising, pushing malicious pages up search results with SEO poisoning, or lacing sites a specific community frequents — a watering hole attack. The page then fingerprints each visitor: outdated browsers may be exploited directly, while patched ones are shown a social-engineering overlay. The "fake update" lure has proven durable — campaigns like SocGholish built an entire ecosystem on bogus browser-update prompts — and its newest descendant, ClickFix, does away with the file entirely by talking the visitor into pasting a command into their own terminal. Payloads are typically infostealers, loaders, and remote access trojans, which is why one careless click on a familiar-looking site can end with corporate credentials for sale — the pipeline we follow in our infostealer guide.

How to defend against it

Patching is the strongest single control: a fully updated browser and OS removes the silent-exploit path almost entirely, forcing attackers back to persuasion. Browser isolation, DNS filtering, and ad blocking shrink exposure to poisoned pages, and endpoint protection catches the common payloads. What remains is the deception layer, and that belongs to awareness: software updates come from the browser's own updater, never from a web page; no legitimate site asks visitors to run commands to "verify" themselves. Rehearse those reflexes in security awareness training and track who reports fake-update lures, not just who avoids them.

Related terms

MalvertisingMalvertising is the use of online advertising to spread malware or lead users to phishing pages, often through legitimate ad networks and search ads.Watering Hole AttackA watering hole attack compromises a website a target group already trusts and visits, infecting visitors instead of approaching them directly.SEO PoisoningSEO poisoning manipulates search rankings so malicious sites appear as top results, luring users to fake downloads, login pages, and support numbers.ClickFixClickFix is a social engineering attack that uses fake CAPTCHAs or error prompts to trick victims into pasting and running malicious commands themselves.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo