166 terms · 75/46/45
Threat № 069 · class: physical / IoT

USB Drop Attack

A USB drop attack uses human curiosity and the habit of plugging an unknown device into a computer to see what is on it. The attacker leaves a USB stick or device where an employee will notice it: a car park, a corridor, a reception desk, a meeting room, a bag of promotional material.

Term

description · examples · notes

A USB drop attack uses human curiosity and the habit of plugging an unknown device into a computer to see what is on it. The attacker leaves a USB stick or device where an employee will notice it: a car park, a corridor, a reception desk, a meeting room, a bag of promotional material.

Description

The USB need not be ordinary storage. It can carry malware, a fake document, a script, or a device that presents itself to the computer as a keyboard and types commands within seconds. The user thinks they have found a flash drive; the computer sees a device it trusts more than it should.

This attack is old but has not gone away, because it steps around part of the network protection. The attacker sends no email and jumps no company firewall; they rely on the victim carrying it in themselves, behind every technical barrier.

Examples

  • A USB device left in the car park in front of the company holds a file a careless user opens out of curiosity.
  • A Rubber Ducky device presents itself as a keyboard and executes commands automatically.
  • A USB brought back from a conference is used on a work computer without a check.

Notes

  • An unknown USB is not a lost item to be examined but unknown hardware.
  • Control of USB ports and blocking unapproved devices look tedious right up until somebody plugs in a keyboard that is not a keyboard.
Composite
Wikipedia

Techniques

carried out with 2

Techniques used to carry it out. Select one to open its page.

Defenses

countered by 3

How it is defended against. Select one to open its page.