Drive-By Download

A malware delivery method where malicious software is automatically downloaded to a device simply by visiting a compromised website.

A drive-by download is an unintentional download of malicious software that occurs simply by visiting a compromised or malicious website, without any user interaction beyond navigating to the page. Unlike social engineering attacks that require the victim to click a link or open a file, drive-by downloads exploit vulnerabilities in web browsers, browser plugins, or operating systems to silently install malware. The user may have no indication that anything malicious has occurred.

Drive-by download attacks typically exploit vulnerabilities in common browser plugins (such as Java, Flash, or PDF readers), JavaScript engines, or the browser itself. Attackers either compromise legitimate websites by injecting malicious code (often through XSS vulnerabilities or compromised ad networks) or create dedicated malicious pages and drive traffic to them through SEO poisoning, malvertising, or spam. The malicious code uses exploit kits — automated tools that probe the visitor's browser for known vulnerabilities and deliver appropriate payloads. If a vulnerability is found, the exploit kit downloads and executes malware without user consent or awareness.

The malware delivered through drive-by downloads can include ransomware, banking trojans, spyware, cryptocurrency miners, or backdoors. The scale can be enormous: a single compromised advertising network can expose millions of users to exploit kit traffic. While the decline of vulnerable plugins like Flash has reduced some attack surface, drive-by downloads continue through browser and OS vulnerabilities. Defense requires keeping browsers and plugins updated, using browsers with built-in sandboxing, deploying ad blockers to reduce malvertising exposure, and running endpoint protection with behavioral detection capabilities.

Examples

  • A popular news website is compromised, and visitors are silently redirected to an exploit kit that installs a banking trojan.
  • A malicious advertisement on a legitimate site exploits a browser vulnerability to install cryptocurrency mining malware.
  • Visiting a search result leads to a page that exploits an unpatched PDF plugin vulnerability to install a backdoor.

Prevention

  • Keep web browsers and all plugins updated with the latest security patches.
  • Use a modern browser with built-in sandboxing and automatic security updates.
  • Deploy ad blockers and script blockers to reduce exposure to malvertising and exploit kits.
  • Run endpoint protection with behavioral analysis to detect and block exploit attempts.

Try These Tools

Security Headers Checker

Related Terms

Malware Zero-Day Exploit Cross-Site Scripting (XSS) Watering Hole Attack

Stay Protected with Beacky

Detect phishing clones of your website in real-time with invisible beacon technology.

Get Started with Beacky