Could removable media contain malicious software?¶
Yes. Removable media can contain malicious software or behave in a way that compromises the connected system.
Avoid this assumption: Risk exists only if someone manually opens an infected file. Some devices may exploit automatic processes, imitate trusted hardware or prompt the user to run software.
Malicious content may include executable files, scripts, documents with active features, shortcuts, hidden files or modified installers.
The device itself may also present as a keyboard or network adapter and issue commands.
Do not connect suspected media to a normal operational, personal or evidence-management computer.
Do not rely solely on the device label, filename or apparent purpose.
Record where it was found, who supplied it, how it was packaged and whether anyone has already connected it.
Capture any warning, unusual behaviour, security alert or system change associated with prior use.
Where malware is suspected, isolate the affected host system proportionately and seek cyber or forensic support.
Do not delete, quarantine or clean files from the original media.
An antivirus result may be useful, but it does not prove the device is safe or identify who placed the content there.
Likewise, the presence of malware does not automatically prove malicious intent by the person carrying the device.
Preserve the media and any affected computer separately, maintaining continuity for both.
Record every handling and examination decision.
Operational takeaway¶
Treat unknown removable media as potentially hostile, avoid ordinary connection or cleaning, and preserve both the media and any system already exposed to it.