Live data from Hacker News

Scientist-developed malware covertly jumps air gaps using inaudible sound

arstechnica.com

1–10 of 60 posts

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#3
post #2

Note that using ultrasound as a communication mechanism, which is what's being described here, is very different from using it as an infection vector .

In other words, the "target" computer has to be actively listening?

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#4
I love this sci-fi by way of anachronism stuff.

The transfer rate of ~20 bytes per second is tiny, but of course that tiny amount could be the difference between two machines appearing to communicate and not appearing to. If your network traffic is confirmed to be zero, that's a state of confidence that's easy to take advantage of, and a deeply-rooted bit of malware like this could strike in extremely subtle and devious ways.

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#5
post #2

Note that using ultrasound as a communication mechanism, which is what's being described here, is very different from using it as an infection vector .

In other words, the "target" computer has to be actively listening?

Not only that, but the listening application must have some kind of exploitable vulnerability.

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#6
post #2

Note that using ultrasound as a communication mechanism, which is what's being described here, is very different from using it as an infection vector .

In other words, the "target" computer has to be actively listening?

That's how it seems to me. But a well-hidden bit of malware won't have a problem turning on the mic for a few seconds on the hour every hour to listen for a handshake chirp or the like. It's a limitation, but far from an insurmountable one.

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#7
What else would you exfiltrate/steal besides passphrases and private keys? Serial numbers/IPs/hostnames of any discovered devices on the air-gapped network?

Send to the airgapped computer(s) software updates and new commands to run? 20 bytes per second is enough for that, or is it bits? A shellcode is about 40bytes or less.

I guess if you want to guard against this the reasonable thing to do would be to physically take out the mic and speakers of any to-be-secure-computers. Or have one computer listen in on these high frequencies on the perimeter or whatever. Would be interesting to discover chats.

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#8
post #2

Note that using ultrasound as a communication mechanism, which is what's being described here, is very different from using it as an infection vector .

In other words, the "target" computer has to be actively listening?

Yes. To call this result "unsurprising" would dignify it unduly.

Re: Scientist-developed malware covertly jumps air gaps using inaudible sound

#9
post #7

What else would you exfiltrate/steal besides passphrases and private keys? Serial numbers/IPs/hostnames of any discovered devices on the air-gapped network? Send to the airgapped computer(s) software updates and new commands to run? 20 bytes per second is enough for that, or is it bits? A shellcode is about 40bytes or less. I guess if you want to guard against this the reasonable thing to do would be to physically ta…

You could also broadcast noise in those frequencies at a loud enough volume to block any signal.
Post reply on HN