A USB drop attack involves leaving infected USB drives in public places to trick unsuspecting users into plugging them in and compromising their systems. Recognizing this threat and handling unknown removable media with caution are essential practices for maintaining network security.
USB Drop Attacks
Sometimes curiosity gets the best of us. If you were to find a USB drive, what would you do with it? Would you be curious about what's on it? Would you plug it into your computer so you can explore it? Would you keep it so that way you have a free USB drive that you can use in the future?
A USB drop is when an adversary leaves an infected USB drive in a public place. For someone to carry out this attack, first they would need a USB drive — or probably many USB drives — and then put viruses on those USB drives. Then they would go and leave them in places where people would plug them into their computer.
Let's say I'm targeting a specific business. I would find maybe a parking lot that those employees park in, or maybe a coffee shop nearby, somewhere those employees frequent often, and then I would put those USB drops there. They would get curious about what's on the USB drive, they plug it into their computer, and that's what would install that virus. Now it would be on the machine and would leverage whatever network that they're on.
This is one reason why I'd never plug a foreign USB, or any kind of other removable media, into the computer. In fact, there would be times when people would give me stuff. One time my boss gave me a USB drive — there was some data that he was concerned about, or he wanted to know if there was certain data on it, or he asked me to explore it. I didn't use my main laptop. What I did is I found a laptop that we were going to decommission soon that we didn't really care about, and I plugged it into there to explore what was on it. That way, if that machine got infected, it wasn't my personal machine, the one that I used on a day-to-day basis; it would infect this machine that we were going to wipe anyway. So I would always be very cautious whenever I would utilize these USB drives or any other kind of removable media.
I'll also say that we would run tests on the company's employees. In one of the places I worked in the past, we did USB drops all around the office to see who would pick up those USBs and plug them into the machine. It was a test that we, as the IT department, ran against the employees of the company.
So a USB drop is leaving an infected USB drive in public spaces in hopes that a victim will plug that into their computer, infecting the computer and us gaining access to that network.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →