← All terms

USB Drop Attack

A USB drop attack seeds infected flash drives where targets will find them, exploiting curiosity to get malware or keyloggers inside a network.

A USB drop attack is the physical-world cousin of the phishing email: an attacker seeds malware-laden USB flash drives in places a target is likely to find them — parking lots, lobbies, restrooms, conference swag tables — and waits for curiosity to do the rest. It is the canonical form of baiting, and it remains effective because it bypasses the email gateway entirely and arrives with a built-in pretext: a found object that might belong to a colleague, labeled something irresistible like "Salaries Q3" or "Layoff plan."

How it works

The dropped drive carries one of several payloads. The simplest is a malicious document or executable that installs a keylogger or remote-access trojan when opened. More sophisticated drives impersonate a keyboard (a "Rubber Ducky"–style HID attack) and inject keystrokes the moment they are plugged in — no file needs to be opened at all. Others exploit autorun behavior on poorly configured systems or stage a credential-harvesting shortcut that phones home. Research has repeatedly shown the human side works: in a well-known University of Illinois study, nearly half of several hundred dropped drives were plugged in, many within hours of being seeded.

Variants extend beyond the parking lot. Attackers mail branded "gift" drives to specific employees, hand them out at trade shows, or combine the drop with tailgating to place drives on desks inside the building. The 2020 FIN7 campaign that mailed fake Best Buy gift-card USB packages to US businesses showed the technique scales as targeted attack, not just opportunistic mischief.

How to defend against it

  • Kill the technical path. Disable autorun, restrict removable storage via endpoint policy to approved encrypted devices, and alert on new USB HID devices appearing on corporate machines.
  • Give finders a safe path. Publish a simple rule — found media goes to IT, never into a port — and make handing a drive in feel like a catch, not a chore.
  • Test the reflex. Seeded-drive exercises alongside phishing simulations reveal whether the policy survives contact with curiosity, and a plugged-in test drive is a teachable moment that belongs in your incident response playbook rather than a disciplinary file.

Related terms

BaitingBaiting is a social engineering attack that lures victims with a tempting item — such as a USB drive, free download, or prize — to deliver malware or harvest credentials.KeyloggerA keylogger is software or hardware that secretly records keystrokes to steal passwords, messages, and card numbers, feeding credential-based attacks.Tailgating (Piggybacking)Tailgating is a physical social engineering attack where an unauthorized person follows an employee through a secured door into a restricted area.Insider ThreatAn insider threat is the risk that employees, contractors, or partners with legitimate access cause harm — maliciously, negligently, or after being compromised.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo