Attack technique

Baiting

An attack that lures victims with a tempting offer, such as free software or a found USB drive, to get them to install malware or expose credentials.

Definition

Baiting is a social engineering attack that dangles something appealing, such as a free movie download, a gift card, or a USB drive labeled with an enticing name, to persuade a victim to take an action that compromises security. The bait delivers malware or leads the victim to a credential harvesting page once they take it.

In a typical baiting attack, a malicious actor leaves infected USB drives in a parking lot, lobby, or elevator, hoping an employee will plug one into a work computer out of curiosity. Online, the bait is often a free download, pirated software, or a fake prize notification that installs malware when opened. The attacker relies on the target's curiosity or desire for something free, which lowers normal caution about unknown files or devices.

Baiting works because it exploits basic human impulses rather than technical weaknesses, so it can succeed even in organizations with strong perimeter security. Physical baiting is a particular concern in office environments with shared spaces, such as bank branches or government buildings, where an unfamiliar USB drive can go unnoticed among staff belongings. A single infected device connected to an internal network can give an attacker a foothold for further compromise.

Organizations should establish and enforce a policy against plugging in unknown removable media, and disable autorun on all endpoints. Employees should be trained to report found devices to IT rather than inspecting them personally, and to treat unsolicited free offers online with the same skepticism as suspicious email links. Endpoint protection that blocks unauthorized USB devices adds a technical layer of defense against this human-focused tactic.

At a glance

Severity
Medium
Prevalence
Common in offices with shared spaces
Primary targets
Employees with physical device access and general internet users tempted by free offers

How it works

  1. 1

    Enticing offer: the attacker dangles something appealing, such as a free download, gift card, or a USB drive with a tempting label.

  2. 2

    Placement or delivery: infected drives are left in parking lots, lobbies, or elevators, or the bait is offered online as a free download or fake prize.

  3. 3

    Curiosity or greed: the target's desire for something free lowers their normal caution about unknown files or devices.

  4. 4

    Action taken: the victim plugs in the device or opens the download.

  5. 5

    Compromise: malware installs, or the victim is redirected to a credential-harvesting page.

Warning signs

  • An unfamiliar USB drive or storage device found in a public or shared area
  • An unsolicited offer of free software, media, or a prize online
  • Pressure or curiosity nudging you to act on something unverified
  • A download that requires disabling security warnings to open
  • A label or prize notification that seems too good or oddly specific

How to defend

  • Never plug in an unknown USB drive or removable media; report found devices to IT instead
  • Disable autorun on all endpoints
  • Treat unsolicited free offers online with the same skepticism as suspicious email links
  • Use endpoint protection that blocks unauthorized USB devices
  • Train employees to recognize baiting as a tactic in both physical and online settings

Real-world example

An employee at a government office finds a USB drive labeled "Gaji dan Bonus 2026" in the parking lot. Curious, they plug it into their work computer, unknowingly installing malware that gives an attacker a foothold on the internal network.

How Claro helps

Claro's awareness modules cover baiting scenarios, including physical media risks, so employees learn to pause before plugging in or downloading anything unverified.

Frequently asked questions

What is the difference between baiting and phishing?

Phishing typically arrives as a deceptive message asking for action. Baiting instead offers something enticing, like a found USB drive or free download, that itself carries the malicious payload once accepted.

Why do infected USB drives still work as an attack?

They exploit curiosity rather than technical weaknesses, so they can succeed even in organizations with strong perimeter security, especially in shared spaces where an unfamiliar drive can go unnoticed.

What should I do if I find an unknown USB drive at work?

Do not plug it into any computer. Hand it to your IT or security team so they can inspect it safely.

Does disabling autorun stop baiting attacks?

It removes one common trigger, automatic execution when a drive is inserted, but does not stop an employee from manually opening a malicious file on the drive, so training and reporting habits remain essential.

Reduce your human risk

Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.

Request a demo