Researchers prove that light, sound can activate mobile malware

Share this article:

Let there be light. Or maybe not.

Researchers have discovered a way to trigger and control malware on smartphones using sensory channels, like light, vibrations, music or other sounds.

According to a paper (PDF) published by researchers at the University of Alabama at Birmingham (UAB) and presented earlier this month at a security conference in China, this is possible because of the advanced sensory technology found in modern cell phones.

The paper, titled “Sensing-Enable Channels for Hard-to-Detect Command and Control of Mobile Devices,” described one example in which music that blares from a speaker could cause compromised smartphones to carry out malicious activities at a sports event.

Attackers could instruct the malware to perform actions such as launch distributed denial-of-service attacks, interfere with other non-mobile networks in range, or hijack a user's phone to do a range of annoying or disruptive things, including calling other phones.

Smartphones, as well as tablets and some laptops, are equipped with advanced sensors that make for “an appealing platform for out-of-band communication among malware-infected devices, as well as between the botmaster owner and infected devices,” the paper said.

The researchers were able to trigger mobile phones from as much as 55 feet away, and built a proof-of-concept Android application, which was installed on an HTC Evo 4G smartphone.

John-Paul Power, a researcher at Symantec, responded to the paper's publication with a Thursday blog post that said anti-malware software should still be capable of detecting malware, regardless “of the means in which it receives its communication.”

So, if an attacker was clever enough to make use of these tricks, it would make for an interesting story, or possibly bragging rights, but wouldn't give them a pass to wreak havoc undetected.

Share this article:

Next Article in News

Sign up to our newsletters

More in News

Research shows vulnerabilities go unfixed longer in ASP

Research shows vulnerabilities go unfixed longer in ASP

A new report finds little difference in the number of vulnerabilities among programming languages, but remediation times vary widely.

Bill would restrict Calif. retailers from storing certain payment data

The bill would ban businesses from storing sensitive payment data, for any long than required, even if it is encrypted.

Amplification, reflection DDoS attacks increase 35 percent in Q1 2014

Amplification, reflection DDoS attacks increase 35 percent in ...

The Q1 2014 Global DDoS Attack Report reveals that amplification and reflection distributed denial-of-service attacks are on the rise.