Huh, I was thinking someone could buy up a ton of cheap usb sticks, load this on there, have it autorun, and then have the payload sent to a server over HTTPS in AWS (who is going to block HTTPS traffic to AWS? everyone runs out of there) that would catch it and notify the attacker via webhook.
Then go sprinkle them around the SFBA.