pith. sign in

arxiv: 1803.03422 · v2 · pith:3WHW43VBnew · submitted 2018-03-09 · 💻 cs.CR

MOSQUITO: Covert Ultrasonic Transmissions between Two Air-Gapped Computers using Speaker-to-Speaker Communication

classification 💻 cs.CR
keywords communicationcomputersdataheadphonesmicrophonesspeakersair-gappedcovert
0
0 comments X
read the original abstract

In this paper we show how two (or more) airgapped computers in the same room, equipped with passive speakers, headphones, or earphones can covertly exchange data via ultrasonic waves. Microphones are not required. Our method is based on the capability of a malware to exploit a specific audio chip feature in order to reverse the connected speakers from output devices into input devices - unobtrusively rendering them microphones. We discuss the attack model and provide technical background and implementation details. We show that although the reversed speakers/headphones/earphones were not originally designed to perform as microphones, they still respond well to the near-ultrasonic range (18kHz to 24kHz). We evaluate the communication channel with different equipment, and at various distances and transmission speeds, and also discuss some practical considerations. Our results show that the speaker-to-speaker communication can be used to covertly transmit data between two air-gapped computers positioned a maximum of nine meters away from one another. Moreover, we show that two (microphone-less) headphones can exchange data from a distance of three meters apart. This enables 'headphones-to-headphones' covert communication, which is discussed for the first time in this paper.

This paper has not been read by Pith yet.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. ("Oops! Had the silly thing in reverse")---Optical injection attacks in through LED status indicators

    cs.CR 2019-06 unverdicted novelty 7.0

    LED status indicators on microcontrollers can act as optical receivers, enabling data injection attacks with bandwidth approaching 1 Mbit/s under realistic compromise conditions.