In this article
- The short version
- What happened
- What the malware did
- The response: Operation Buckshot Yankee
- Who was responsible?
- What this means for you
- Sources
The short version
- In 2008 a USB flash drive carrying malware was inserted into a laptop at a US base in the Middle East.
- The worm, called Agent.btz, spread onto networks run by US Central Command, including classified and unclassified systems.
- The Pentagon's clean-up was named Operation Buckshot Yankee and took more than a year.
- The US government did not publicly say who was responsible at the time. A later US report pointed to Russian intelligence services. See below for the wording.
What happened
US Deputy Defense Secretary William Lynn confirmed the incident publicly in an article for Foreign Affairs, reported on August 25, 2010. He said a single infected flash drive was inserted into a laptop at a US military base in the Middle East, and that the malicious code on it had been placed there by a foreign intelligence agency. From that one laptop the malware reached a network run by US Central Command and spread without being noticed, across both classified and unclassified systems.
Some retellings say the drive was left in a car park for someone to find. The sources we checked do not confirm how the drive reached the laptop, so we have not repeated that detail.
What the malware did
Agent.btz is reported to be a variant of an older worm called SillyFDC, which spread whenever an infected removable drive was plugged into a computer. It could scan an infected computer for certain data and open a backdoor to a remote server. Lynn described the result as a “digital beachhead” from which information could be sent out.
The sources disagree on one point. One report says classified and unclassified data was sent to servers under foreign control. Another says Lynn did not say whether any data was actually stolen. We cannot confirm which is right, so we are telling you the sources differ.
The response: Operation Buckshot Yankee
- The Pentagon banned removable drives and switched off the Windows AutoPlay feature to slow the spread. Wired reported this on November 19, 2008. The ban was later lifted.
- The clean-up, Operation Buckshot Yankee, took more than a year.
- Reports link the incident to the later creation of US Cyber Command.
Who was responsible?
Lynn did not name the intelligence agency in 2010. Chinese and Russian hackers were suspected early on. In December 2016 a joint FBI and Department of Homeland Security report attributed Agent.btz to “one or more” Russian civilian and military intelligence services. That wording does not name a single unit, and we have not seen a formal public accusation beyond that report. Wired reported in 2010 that some insiders doubted it was a foreign spy operation. Treat attribution as reported, not settled.
What this means for you
The US military has strong security and still lost control of its networks because one person plugged in one drive. The same weakness is in your home and office. Turning off AutoPlay and refusing unknown drives are the two cheapest protections you have.
- Never plug in a USB drive you found, or one handed to you by a stranger. A “lost” drive left where you will find it is a classic trap.
- Turn off AutoPlay. In Windows, open Settings, search for “AutoPlay” and set it to take no action. That stops a drive from launching anything by itself.
- Keep your computer and apps updated. Stuxnet-style tricks rely on flaws that updates close.
- Use your own charger and cable in public. If you must use a public charging point, a small USB “data blocker” lets power through but blocks data.
- Share files another way. Cloud links and email attachments you trust are safer than passing a drive around.
- At work, hand found drives to IT. Do not “just check what is on it”.
Sources
- Computerworld: Infected USB drive blamed for ’08 military cyber breachAugust 25, 2010
- Threatpost: Buckshot YankeeJune 30, 2011
- Wikipedia: 2008 malware infection of the United States Department of Defense (cites Wired November 19, 2008 and the FBI and DHS report of December 29, 2016)page checked October 9, 2026
Published October 9, 2026. We only include facts we could confirm in the sources above, and we say clearly where something is reported but not confirmed.
Frequently asked questions
What was Agent.btz?
A worm that spreads through removable drives. It infected US military networks in 2008 after an infected USB drive was plugged into a military laptop.
Was the Agent.btz attack confirmed by the US government?
Yes. Deputy Defense Secretary William Lynn confirmed the breach in an article published in August 2010. The government did not publicly name the culprit at that time.
Why did the Pentagon ban USB drives?
To slow the spread of the worm. The ban was reported on November 19, 2008 and was later lifted.
How can I protect myself from USB malware?
Do not use drives you do not trust, turn off AutoPlay, keep your computer updated and use your own charger in public.