A malicious drive can deliver code on first contact, then quietly collect host details until the device is reconnected. On later insertions, the malware may begin stealing files automatically and forwarding them when the drive returns to an internet-connected machine. The result is a slow, physical exfiltration path that bypasses normal network controls.
How a tainted USB drive turns an air gap into a delivery path
An air gap blocks network reachability, but it does not block removable media, host execution, or human workflow. Once a drive is trusted on a protected system, it can act as the bridge that carries code inward and data outward. The key issue is not just infection, but persistence across repeated physical transfer between isolated and connected environments.
The first insertion is often about establishing presence and learning the environment. The malware can identify host details, mounted paths, document types, and other filesystem clues, then wait for a later opportunity to move data. That staged behaviour is what makes the attack more than a one-time payload drop.
On subsequent insertions, the drive can become a courier. If the malware has permission to read local files or capture clipboard, metadata, or cached content, it can package that material onto the drive and carry it back to a machine with internet access. The exfiltration may look like ordinary file activity unless the organisation monitors removable-media use closely.
Why this bypasses normal network controls
Air-gapped environments are usually designed around network denial, but USB abuse sidesteps the network boundary entirely. The attacker does not need a live remote session, a firewall exception, or a routed path into the enclave. The transfer mechanism is physical access plus trust in a device that can execute code, present storage, or impersonate a benign peripheral.
This is why media controls matter as much as perimeter controls. A locked-down network can still be exposed if the endpoint will auto-run content, trust unknown devices, or allow unrestricted read and write access to removable storage. When that happens, the attack path becomes a process issue as much as a technical one.
In practice, the most dangerous part is the delay between compromise and discovery. A tainted drive may not trigger obvious alarms on first use, then quietly wait until the next cross-domain trip to leak data. That makes it harder to distinguish an operational USB workflow from a covert collection channel.
Risk and Threat Considerations
The main risk is that a removable device can convert a supposedly isolated system into a source of malware spread and data loss. Once the drive is trusted in both directions, the attacker gains a slow, human-mediated exfiltration path that is difficult to spot with network-only monitoring.
Failure mechanism: The device is inserted into a protected host, the malware executes or stages itself, then persists on the media and uses later insertions to collect and export files when the drive returns to an internet-connected system.
Impact: Sensitive data can leave the air-gapped environment without any conventional outbound connection, and the same path can also seed infection into other systems that accept the media later.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1091 — Replication Through Removable Media | Covers malware spreading or staging through USB and other removable media. |
| T1025 — Data from Removable Media | Applies when data is collected from a USB device used to move files out of an isolated host. | |
| Recommendation — Monitor removable-media execution and isolate suspicious USB activity before it can replicate across zones. Inspect removable-media access and block unauthorized file collection from portable storage. | ||
| CIS Controls v8 | CIS 10 — Data Recovery | Supports recovery planning when malware or exfiltration originates from removable media. |
| CIS 8 — Audit Log Management | Relevant because USB insertions and file transfers need traceable logging to detect covert exfiltration. | |
| Recommendation — Limit removable-media exposure and preserve recoverability of affected hosts and data. Log removable-media events and review them for unusual cross-domain file movement. | ||
Practitioner Guidance
What to verify: Treat removable-media policy as an endpoint control, not only a physical-security rule. Verify whether autorun is disabled, whether write access is restricted, and whether USB usage is logged in a way that ties media events to specific hosts and users.
What practitioners underestimate: Air gaps fail most often at the handoff points, not at the firewall. A drive that moves between zones creates a reusable trust bridge, so the real control question is whether the organisation can detect, quarantine, and inspect that bridge before each crossing.
Practitioner takeaway: If removable media is allowed anywhere near an isolated network, assume the boundary can be crossed and design controls for inspection, monitoring, and least-privilege media handling rather than relying on isolation alone.
Related resources from NHI Mgmt Group
- How should organisations control USB use for CUI in air-gapped environments?
- What happens when a vulnerable gateway is used to bridge cloud requests into an on-premises network?
- What happens when an AI assistant is deployed across cloud, on-prem, and air-gapped environments without security controls?
- What happens when stolen developer credentials are used to reach production systems?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 19, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org