Drive-by Download
A drive-by download infects a device through a compromised or malicious web page, with little or no user action beyond visiting the site.
A drive-by download is an infection delivered by a web page rather than an attachment: the victim visits a site — often a legitimate one that has been compromised — and malware is downloaded and executed with little or no further interaction. In the classic form, an exploit kit probes the visitor's browser and plugins for known vulnerabilities and silently installs its payload when it finds one. In the more common modern form, the page uses deception instead of an exploit: a fake browser update, a bogus codec or font error, or a counterfeit CAPTCHA tricks the visitor into approving the download themselves.
How it works
The attacker first needs traffic. They get it by compromising established websites, buying poisoned ads through malvertising, pushing malicious pages up search results with SEO poisoning, or lacing sites a specific community frequents — a watering hole attack. The page then fingerprints each visitor: outdated browsers may be exploited directly, while patched ones are shown a social-engineering overlay. The "fake update" lure has proven durable — campaigns like SocGholish built an entire ecosystem on bogus browser-update prompts — and its newest descendant, ClickFix, does away with the file entirely by talking the visitor into pasting a command into their own terminal. Payloads are typically infostealers, loaders, and remote access trojans, which is why one careless click on a familiar-looking site can end with corporate credentials for sale — the pipeline we follow in our infostealer guide.
How to defend against it
Patching is the strongest single control: a fully updated browser and OS removes the silent-exploit path almost entirely, forcing attackers back to persuasion. Browser isolation, DNS filtering, and ad blocking shrink exposure to poisoned pages, and endpoint protection catches the common payloads. What remains is the deception layer, and that belongs to awareness: software updates come from the browser's own updater, never from a web page; no legitimate site asks visitors to run commands to "verify" themselves. Rehearse those reflexes in security awareness training and track who reports fake-update lures, not just who avoids them.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo