Skip to main content
Threat playbook

Category: Malware Delivery

Drive-by downloads in the browser

A drive-by download is when a visit to a website triggers an unwanted download or malware installation—often without the user intending to download anything.

Quick answer

Browsers are complex: a single vulnerable plugin, extension, or browser component can turn “just browsing” into an endpoint infection path.

For drive-by content and risky downloads, isolation keeps untrusted web execution off the endpoint and makes each browsing session disposable.

Last updated

2026-01-29

How it usually happens in the browser

  • A user lands on a compromised site, malvertising landing page, or an attacker-controlled page.
  • Scripts fingerprint the browser and environment to decide which exploit or download prompt to show.
  • The site triggers a download automatically or nudges the user into clicking a deceptive prompt.
  • If a vulnerability is present, the payload can execute or drop additional malware.

What traditional defenses miss

  • Not every malicious payload looks like an executable—some are scripts, archives, or staged downloads.
  • Browser exploits can execute without obvious user actions; “don’t click downloads” isn’t always enough.
  • Endpoint tools may detect after execution rather than preventing the browser from reaching the payload.

How isolation changes the game

  • Isolation keeps risky web execution away from endpoints by running content in a separate container and streaming the safe output.
  • Downloads can be blocked, scanned, or routed through controlled workflows from the isolated environment.
  • Deleting isolated sessions reduces persistence and leftover state from risky browsing events.

Operational checklist

  • Block automatic downloads and restrict download types in risky browsing contexts.
  • Route unknown domains and ad-driven traffic into isolation by default.
  • Keep browsers and extensions patched; reduce the extension footprint across the org.
  • Add file-scanning gates for any downloads that must reach endpoints.
  • Instrument alerts for “download started” events from high-risk sources and investigate quickly.

FAQs.

References

  1. 01
  2. 02

Keep exploring

Access anything.
Expose nothing.

Legba is a disposable real browser: it spawns a clean session, does the work, and destroys itself on close.

chromium / real fingerprint · residential ip · burn on close

Real browser. Real IP. Real page. Spawn a session. Do the work. Destroy it. Off your device. Off your stack. Gone on close.