Skip to content
Skip to main content
First Response & Preservation Technical Explainer

Could removable media contain malicious software?

Yes. Removable media may carry malicious files or present itself as hardware that can compromise a connected system, so unknown media should be handled as both potential evidence and a security risk.

The risk is not limited to opening a program

Malicious content can be hidden in executables, scripts, shortcuts, installers or documents with active features. A USB device may also imitate a keyboard or network adapter and send input as soon as it is attached. Automatic scanning, previews and operating-system vulnerabilities can create exposure before a user deliberately runs anything.

Do not test suspected media on a normal operational or evidence-management computer, and do not delete, quarantine or clean the original. A benign antivirus result cannot establish that the device is safe: signatures and scanning scope are limited, and the device may have functions the scanner does not examine.

Preserve the media and any exposed host

Record where the item came from, who supplied or possessed it, its packaging and any known previous connections. Capture warnings, security alerts, unusual input, network activity or other changes on a host that has already been exposed. Both items may require separate preservation and continuity records.

Malware findings can explain technical behaviour, but do not by themselves prove who placed the content on the device or that its possessor intended harm.

Key takeaway

Keep unknown removable media away from ordinary systems, preserve rather than clean it, and assess any connected host without turning a malware finding into unsupported attribution.

Reference: FRP-150First Response & Preservation