It looks like you're using an Ad Blocker.

Please white-list or disable AboveTopSecret.com in your ad-blocking tool.

Thank you.

 

Some features of ATS will be disabled while you continue to use an ad-blocker.

 

Scientists have developed malware that jumps air gaps using inaudible sound

page: 1
6

log in

join
share:

posted on Dec, 2 2013 @ 06:22 PM
link   
Some of you may have read one of the threads last month regarding BadBIOS:

Meet “badBIOS,” the mysterious Mac and PC malware that jumps airgaps
If Dragos Ruiu isn't crazy, "badBIOS" is the worst thing to infect a computer, ever.

One of the more interesting claims regarding this this new malware, as reported by Dragos Ruiu, is its ability to communicate between two infected PCs by transmitting HF sound, using the computers' speakers and mics.

Today I came across the following on Ars Technica:


Computer scientists have developed a malware prototype that uses inaudible audio signals to communicate, a capability that allows the malware to covertly transmit keystrokes and other sensitive data even when infected machines have no network connection.

The proof-of-concept software—or malicious trojans that adopt the same high-frequency communication methods—could prove especially adept in penetrating highly sensitive environments that routinely place an "air gap" between computers and the outside world. Using nothing more than the built-in microphones and speakers of standard computers, the researchers were able to transmit passwords and other small amounts of data from distances of almost 65 feet. The software can transfer data at much greater distances by employing an acoustical mesh network made up of attacker-controlled devices that repeat the audio signals.



The researchers developed several ways to use inaudible sounds to transmit data between two Lenovo T400 laptops using only their built-in microphones and speakers. The most effective technique relied on software originally developed to acoustically transmit data under water. Created by the Research Department for Underwater Acoustics and Geophysics in Germany, the so-called adaptive communication system (ACS) modem was able to transmit data between laptops as much as 19.7 meters (64.6 feet) apart. By chaining additional devices that pick up the signal and repeat it to other nearby devices, the mesh network can overcome much greater distances.


source

The article does a very poor job of explaining that while this represents a novel (and very low bandwidth @ 20bps) mode of communication, it does not constitute a new vector for infection. That is to say, both PCs would need to have been already infected through some other means and only after being infected could such communication take place.

What it does mean is that in addition to pulling the network cable, it might be a good idea to disable built-in mics and unplug the speakers when removing an infected PC from your network.



posted on Dec, 2 2013 @ 06:29 PM
link   
reply to post by theantediluvian
 


Sorry dude, this has already been posted in October in this forum.

Meet “badBIOS,” the mysterious Mac and PC malware that jumps airgaps



posted on Dec, 2 2013 @ 06:34 PM
link   
reply to post by Bassago
 


Correct. Since the OP does direct to that thread, why not just post this new data on that thread?



posted on Dec, 2 2013 @ 06:46 PM
link   

Bassago
reply to post by theantediluvian
 


Sorry dude, this has already been posted in October in this forum.

Meet “badBIOS,” the mysterious Mac and PC malware that jumps airgaps


This thread is actually not about BadBIOS, it is about other researchers creating a proof of concept that demonstrates the feasibility of using HF signals and computers' speakers and mics to communicate covertly. While it doesn't prove Dragos Ruiu's claims, it does somewhat bolster them.

If you'll look back, you'll notice that I started off my post with a reference to BadBIOS and link to that thread .

edit on 2-12-2013 by theantediluvian because: (no reason given)



posted on Dec, 2 2013 @ 07:52 PM
link   

Aleister
reply to post by Bassago
 


Correct. Since the OP does direct to that thread, why not just post this new data on that thread?


Because no one will see it there...



posted on Dec, 2 2013 @ 08:04 PM
link   
reply to post by theantediluvian
 



…it is about other researchers creating a proof of concept that demonstrates the feasibility of using HF signals and computers' speakers and mics to communicate covertly.

Let me tell you whats wrong with that precept.

If one were to make "sounds" that were actually encoded that could enter target computers speakers and infect its software, there would have to already be a program inside the target computer that receives and decodes the "transmission".

Why bother having a "receiver" program in place when you could just infect the computer with a virus over the same channel you infected it with the "receiver" program?

Theres no point in infecting a computer with a program that receives malware programs "over the air". Whats the range on that anyway, in the room?

Wow, highly virulent.



posted on Dec, 2 2013 @ 08:41 PM
link   
reply to post by intrptr
 


As I stated:



The article does a very poor job of explaining that while this represents a novel (and very low bandwidth @ 20bps) mode of communication, it does not constitute a new vector for infection. That is to say, both PCs would need to have been already infected through some other means and only after being infected could such communication take place.

What it does mean is that in addition to pulling the network cable, it might be a good idea to disable built-in mics and unplug the speakers when removing an infected PC from your network.


The important thing is that it represents a covert form of communication between infected PCs that exists even without any network interfaces.



posted on Dec, 2 2013 @ 08:50 PM
link   
reply to post by theantediluvian
 

Whoops, right you are. You did state that. Sorry for not reading thru, I saw something wrong with it right away and spoke the same thing you did. So… theres nothing to worry about.

Unless they infect your mind with advertising, video games, and bloodlust movies.

That needs no encoding, we volunteer…



new topics

top topics



 
6

log in

join