A drive-by download is an attack in which a user is tricked into downloading or executing malicious content from an infected or attacker-controlled website. The victim may believe the file is legitimate, but the real objective is to gain code execution or deliver malware through normal user behavior.
Expanded Definition
Drive-by download describes a compromise path where a website, advertisement, embedded resource, or redirected download causes malware to land on a device with little more than ordinary browsing or file-handling behaviour. The term covers both silent delivery and deceptive delivery that relies on user trust, browser prompts, or software misdirection.
It is narrower than general phishing because the malicious action is triggered by visiting or interacting with web content, not only by opening a message or replying to a lure. It is also broader than a simple malicious download, because the attacker’s goal is often to create an initial execution foothold rather than merely host a bad file. In practice, the boundary is sometimes blurred by browser exploit chains, fake update prompts, and signed but unwanted installers, so usage in the industry is still evolving around the exact delivery path.
For a standards-oriented treatment of web threat categories, the OWASP Non-Human Identity Top 10 is not a direct fit for this term, but OWASP’s broader security taxonomy is often used to frame web-based attack delivery and trust abuse.
Examples and Use Cases
Drive-by download shows up wherever a trusted-looking web experience can be turned into a malware delivery channel:
- A compromised news site or content platform loads malicious advertising or injected script that redirects users to a payload download.
- A fake browser or PDF update page persuades the user to run an installer that appears routine but drops malware instead.
- An attacker-controlled download portal serves a trojanized copy of legitimate software, often packaged to look signed or authentic.
- A malicious landing page chains a browser exploit with an automatic payload fetch, reducing the amount of user interaction needed.
- A temporary compromise of a hosting account or CMS turns an otherwise normal site into a delivery point for one campaign window.
The practical tradeoff is that stronger user friction, safer browsing controls, and restricted execution policies reduce the success rate, but they can also create support overhead when legitimate downloads are blocked or challenged.
Security Implications
Drive-by downloads matter because they convert everyday web access into a code-execution opportunity. The attacker does not need to persuade a target to run an obvious weapon file if the browser, plug-in, update flow, or download path can be abused to make the payload appear expected.
Failure mechanism: the compromise usually depends on one of three recognised patterns: malicious redirection, social engineering that bypasses suspicion, or exploitation of a browser or application weakness during content handling. Once the payload is delivered, subsequent execution can lead to persistence, credential theft, ransomware staging, or broader endpoint compromise.
Impact: the immediate consequence is untrusted code execution on an endpoint, often followed by lateral movement, data access, or further malware deployment. At scale, the pattern can create repeated infections through a single web property, which makes detection and containment more difficult than a one-off file transfer.
NHIMG’s research on Ultimate Guide to NHIs notes that 79% of organisations have experienced secrets leaks, with 77% resulting in tangible damage, which is a reminder that initial endpoint compromise can quickly become a secrets exposure problem.
Domain and Governance Relevance
Drive-by downloads sit at the intersection of web security, endpoint control, and user trust. The term matters because the attack succeeds when an organisation allows ordinary browsing to become a silent software delivery path without sufficient inspection, restriction, or isolation.
In NHI-heavy environments, the downstream concern is often not the first infected workstation but the credentials, tokens, and automation access reachable from that device. A compromised browser session or developer workstation can expose API keys, cloud console sessions, CI/CD access, or other machine credentials that expand the blast radius well beyond the endpoint itself.
That is why the term is relevant to identity governance even though it is not itself an identity concept. When web-delivered malware can reach secrets stores, automation tools, or administrative portals, the organisation’s real control problem shifts from simple malware blocking to protecting non-human access paths from endpoint-originated compromise.
Risk and Threat Considerations
Drive-by downloads are risky because they collapse the distance between passive web browsing and active compromise. The subject is especially dangerous in environments where users have software install rights, browsers are loosely configured, or endpoints can reach sensitive internal resources.
Failure mechanism: attackers exploit trust in familiar websites, download prompts, and update workflows, or they abuse browser and plug-in weaknesses to deliver payloads with minimal friction. The resulting foothold can be used for credential theft, persistence, and follow-on access to connected systems and secrets.
Impact: organisations can lose endpoint integrity, expose stored credentials, and enable lateral movement from a single user action. If the infected device holds access to machine identities or admin tooling, the compromise can quickly become an identity and automation incident rather than only a desktop malware event.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1189 — Drive-by Compromise | Directly names malicious website delivery via user browsing. |
| Recommendation — Monitor web-delivered malware paths and block drive-by compromise at the browser and web gateway. | ||
| CIS Controls v8 | CIS 9 — Email and Web Browser Protections | Covers browser and web controls that reduce malicious download exposure. |
| CIS 10 — Malware Defenses | Applies to detecting and containing malicious code delivered through downloads. | |
| CIS 4 — Secure Configuration of Enterprise Assets and Software | Supports restrictive endpoint and software settings that limit execution paths. | |
| Recommendation — Harden browser and download controls to prevent web-delivered payload execution. Deploy anti-malware and containment controls to detect and stop malicious downloads. Restrict software execution and enforce secure defaults on endpoints and browsers. | ||
| NIST CSF 2.0 | PR.AC-4 — Access Permissions and Authorizations | Compromise often becomes more severe when infected endpoints hold broad access. |
| DE.CM-8 — Malicious Code Detected | Drive-by downloads are often discovered through malware detection and alerting. | |
| Recommendation — Limit endpoint-accessible privileges so a browser compromise cannot reach sensitive systems. Tune detection to flag malicious downloads and unusual post-download execution. | ||
Practitioner Guidance
What to watch for: treat sudden download prompts, unexpected update requests, and redirected web sessions as indicators that the browsing path itself may be hostile. The key operational judgement is whether the endpoint is allowed to execute content from untrusted web origins without isolation or validation.
Governance implication: security teams should align browser controls, download restrictions, and endpoint execution policy with the sensitivity of the credentials and automation accessible from that device. If a workstation can reach secrets, cloud consoles, or build systems, a drive-by infection has materially higher business impact than a generic malware event.
Related resources from NHI Mgmt Group
- How should security teams price identity platforms when non-human identities drive most activity?
- What should IAM teams review when SAML attributes drive access control?
- What breaks when protobuf schema data is allowed to drive code generation?
- When do file download events become useful for investigation and response?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 9, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org