A USB drop attack is one specific form of baiting: leaving infected drives where targets will find and plug them in. Baiting is the general technique of exploiting curiosity with something enticing; the USB drop is its best-documented instance.
Baiting also covers mailed devices, free downloads, fake job offers and abandoned QR codes. The USB drop earns its own name because it has been measured directly, and because it defeats network defences by crossing a physical gap.
Documented cases
- The UIUC study dropped 297 drives, saw about 98% removed from the drop location, and files opened on 45%.
- Operation Buckshot Yankee began with one infected drive in a US military laptop in 2008 and spread the agent.btz worm onto classified networks.
- Stuxnet crossed an air gap into Iran’s Natanz facility on drives carried in by trusted contractors.
The control that breaks it
- Disable or whitelist USB mass storage and HID devices on endpoints.
- Provide a no-questions route to hand in found devices, since the UIUC figures show people will otherwise plug them in.
- Never rely on an air gap alone. Stuxnet and Buckshot Yankee both crossed one.
Related: baiting vs quid pro quo · baiting vs phishing · USB drop attack
Related