TechKnowSurge
VideoSecurityFree

USB Drop

A USB drop attack involves leaving infected USB drives in public places to trick unsuspecting users into plugging them in and compromising their systems. Recognizing this threat and handling unknown removable media with caution are essential practices for maintaining network security.

Complete this video to capture a CTF flag worth 1 point.

About this video

A USB drop attack is a physical social engineering technique in which an attacker loads malware onto one or more USB drives and leaves them in locations where targets are likely to find and use them. The attack exploits natural human curiosity — someone discovers what appears to be a lost or abandoned drive, wonders what is on it, and plugs it into their computer. That single action can silently install malware, giving the attacker a foothold on the infected machine and access to whatever network it is connected to. The simplicity of the method makes it a persistent and effective threat, requiring no technical interaction between the attacker and the victim. Targeted USB drop campaigns are carried out with deliberate placement in mind. An attacker focused on a specific organization might scatter infected drives in employee parking lots, nearby restaurants, or other locations where staff regularly gather. This increases the probability that the person who picks up the drive works at the intended target, making the attack more precise than it might first appear. From a defensive standpoint, the safest policy is to never connect an unknown USB drive or any unverified removable media to a production machine. When handling a suspicious drive is necessary, doing so on an isolated or expendable system that is scheduled for decommission limits the potential damage. Organizations can also evaluate their workforce's susceptibility by conducting internal USB drop exercises, a practice used by security teams to measure awareness and identify employees who may need additional training before a real attacker exploits the same vulnerability.

What you'll learn

What's covered

USB Drop Attacks

Key terms

Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Malware
Software specifically designed to disrupt, damage, or gain unauthorized access to a system.
Virus
Malicious code that attaches itself to legitimate programs and replicates when executed.
Threat Actor
An individual or group responsible for a security incident or attack.
Endpoint
Any device that connects to a network, including computers, smartphones, tablets, and IoT devices.
USB Drop Attack
An attack in which an adversary places an infected USB drive in a public or targeted location, hoping a victim will plug it into a computer and unknowingly install malware.

Topics

Usb Drop Attack Removable Media Security Social Engineering Malware Endpoint Security Cybersecurity Awareness

Transcript

Curiosity and the Found USB Drive

Sometimes curiosity gets the best of us. If you were to find a USB drive, what would you do with it? Would you be curious about what's on it? Would you plug it into your computer so you can explore it? Would you keep it so that way you have a free USB drive that you can use in the future?

A USB drop is when an adversary leaves an infected USB drive in a public place. For someone to carry out this attack, first they would need a USB drive — or probably many USB drives — and then put viruses on those USB drives. Then they would go and leave them in places where people would plug them into their computer.

Let's say I'm targeting a specific business. I would find maybe a parking lot that those employees park in, or maybe a coffee shop nearby, somewhere those employees frequent often, and then I would put those USB drops there. They would get curious about what's on the USB drive, they plug it into their computer, and that's what would install that virus. Now it would be on the machine and would leverage whatever network that they're on.

Why I Never Plug In Foreign Media

This is one reason why I'd never plug a foreign USB, or any kind of other removable media, into the computer. In fact, there would be times when people would give me stuff. One time my boss gave me a USB drive — there was some data that he was concerned about, or he wanted to know if there was certain data on it, or he asked me to explore it. I didn't use my main laptop. What I did is I found a laptop that we were going to decommission soon that we didn't really care about, and I plugged it into there to explore what was on it. That way, if that machine got infected, it wasn't my personal machine, the one that I used on a day-to-day basis; it would infect this machine that we were going to wipe anyway. So I would always be very cautious whenever I would utilize these USB drives or any other kind of removable media.

I'll also say that we would run tests on the company's employees. In one of the places I worked in the past, we did USB drops all around the office to see who would pick up those USBs and plug them into the machine. It was a test that we, as the IT department, ran against the employees of the company.

So a USB drop is leaving an infected USB drive in public spaces in hopes that a victim will plug that into their computer, infecting the computer and us gaining access to that network.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →