An evil maid attack is a security exploit that targets a computing device that has been shut down and left unattended. An evil maid attack is characterized by the attacker's ability to physically access the target multiple times without the owner's knowledge.
By submitting your personal information, you agree that TechTarget and its partners may contact you regarding relevant content, products and special offers.
An evil maid attack might unfold like this:
Scene I: A Chief Financial Officer (CFO) is at a conference. When she goes out to dinner for a little social networking with her peers, she leaves her laptop in her hotel room, confident that any corporate data on the laptop is safe because the hard drive is encrypted.
Scene II: An evil maid (who is actually a corporate spy involved in industrial espionage) spots the CFO leaving her room.
Scene III: The evil maid sneaks into the CFO's room and boots up her laptop from a compromised bootloader on a USB stick. The evil maid then installs a keylogger to capture the CFO's encryption key and shuts the laptop back down.
Scene IV: The CFO returns from dinner and boots up her computer. Suspecting nothing, she enters her encryption key and unlocks the laptop's disk drive.
Scene V: The following morning, while the CFO is downstairs at breakfast, the evil maid comes back and retrieves the CFO's encryption key.
The purpose of the attack may be to steal and sell the key or make changes to the laptop's software right then and there -- but whatever the reason for the attack, the laptop has been touched twice by an unauthorized person without an alarm bell going off.
Besides giving this type of attack a very catchy name, Polish security researcher Joanna Rutkowska successfully demonstrated in 2009 that even full disk encryption (FDE) cannot be counted on to protect a laptop when an attacker has physically access the device. Since then, the name "evil maid" has caught on with security professionals and the label has been used in a general fashion to describe scenarios in which the attacker doesn't simply steal the device -- or access it once to clone the hard drive -- but instead, returns multiple times to wreak havoc.