Skip to content
HackInvasionCybersecurity Knowledge Hub

Credential theft via USB devices: how it works and how to protect yourself

Originally published in 2013 when this blog covered offensive tutorials; rewritten in 2026 with a defensive focus.

The original version of this post was a step-by-step guide to building a USB "rootkit" that silently harvested stored passwords from any Windows computer it was plugged into. Those instructions have been removed. What remains — and what matters — is understanding the threat at a high level so you can defend against it. USB-based credential theft is a real, low-tech attack that still works today in offices, schools, and anywhere strangers have physical access to machines.

How the attack works, at a high level

The concept is simple and requires only brief physical access. An attacker prepares a USB drive with malicious software designed to run when the drive is inserted — historically via the Windows autorun mechanism, today more often through social-engineering tricks that get the victim to click something, or through devices that disguise themselves as keyboards. Once running, the software reads credentials that applications have saved on the machine: browser-stored passwords, saved logins in email and messaging clients, and other cached secrets. The results are written back to the drive, and the attacker walks away with them in seconds.

Two things make this attack potent. First, it needs no network access and leaves little obvious trace to the casual user. Second, many people store passwords in their browsers or stay logged in on shared and work computers, so there is usually something worth stealing.

What defenders and IT teams should watch for

  • Removable-media telemetry: endpoint logs showing USB insertions, especially unknown devices on sensitive machines, followed by unexpected process launches from the removable drive.
  • Antivirus/EDR detections flagging credential-access tools or suspicious executables running from USB paths.
  • Physical indicators: unknown USB drives left in parking lots or desks — a classic social-engineering lure counting on curiosity.
  • Policy violations: users plugging personal drives into locked-down workstations.

Protecting yourself and your organization

  • Disable autorun/autoplay for removable media via Group Policy or device management — this closes the classic silent-execution path. (Modern Windows versions already restrict it, but verify the setting.)
  • Use endpoint device-control policies to restrict or require approval for USB storage devices, especially on sensitive systems. Consider allowing only approved, encrypted drives.
  • Don't let browsers save passwords on shared or work machines — and clear any that are already saved. Store credentials in a reputable, encrypted password manager protected by a strong master password and multi-factor authentication.
  • Enable multi-factor authentication everywhere it matters. Even if a password is stolen, MFA stops the attacker from using it.
  • Lock your screen whenever you step away, and treat physical access as a security boundary: don't leave machines unattended in public areas.
  • Never plug in a USB drive you didn't expect — not found drives, not gifted ones, not drives handed to you by strangers.
  • Keep EDR/antivirus active and updated, and never disable it at someone else's instruction.

If a suspicious USB was plugged in

Disconnect it, do not investigate it on a production machine, and report it to your IT or security team. Assume credentials on that machine may be compromised: change important passwords from a known-clean device, review account activity for unfamiliar logins, and let incident response determine the scope.

Authorization reminder

Security testing involving other people's systems or credentials must only be done with explicit authorization. Building or deploying credential-harvesting tools against systems you don't own is illegal in most jurisdictions — no exceptions for curiosity or "just testing."

1 comments:


EmoticonEmoticon