Security

An experimental new attack can steal data from air-gapped computers using a phone’s gyroscope

Comment

A single lit-up laptop in a dark room.
Image Credits: Justin Paget (opens in a new window) / Getty Images

A security researcher known for devising inventive ways to siphon data from computers that are disconnected from the internet has found a new exploit able to exfiltrate data to a nearby smartphone.

Air-gapped systems are physically segregated and incapable of connecting wirelessly or physically with other computers or network devices. You’ll find them in places where network security is paramount, like critical infrastructure. While uncommon, some techniques developed in recent years can defeat air-gap isolation, like the Mosquito attack, which uses a nearby smartphone’s microphone to receive data. Since then, Apple and Google have introduced permissions settings in iOS and Android that block apps from accessing a device’s microphone, and both operating systems use visual indicators when the microphone is active.

But unlike microphones, gyroscopes — found as standard in most modern smartphones — don’t have the same protections. Gyroscopes are used to detect the rate of rotation of the smartphone, and are widely considered a safer sensor, since neither iOS or Android indicate when they are used or given the option to block access altogether.

Now, the creator of the Mosquito attack has a new technique that uses a smartphone’s gyroscope to pick up inaudible nearby soundwaves and doesn’t rely on using the microphone.

Mordechai Guri, the head of research and development at the Cyber Security Research Center at Ben Gurion University, said in his latest research paper that this new attack, which he calls “Gairoscope,” can exfiltrate sensitive information from air-gapped computers just “a few meters away.”

Like other exploits against air-gapped systems, Guri’s “Gairoscope” proof-of-concept requires close proximity to the air-gapped system. But from there, an attacker could collect passwords or login credentials by listening for sound waves generated from the speakers of an air-gapped system and picked up from the gyroscope of a nearby smartphone.

Guri says these inaudible frequencies produce “tiny mechanical oscillations within the smartphone’s gyroscope,” which can be converted into readable data. He added that an attacker could execute the exploit using a mobile browser, since phone gyroscopes can be accessed using JavaScript.

While the method is still experimental, Guri and his team have recommended some countermeasures aimed at limiting the impact of the new malware, such as eliminating loudspeakers to create an audio-less networking environment and filtering out the resonance frequencies generated by the audio hardware using an audio filter.

More TechCrunch

Today’s scams can be as simple as picking up a phone call. To avoid the next fraud, there are good reasons to let your calls run to voicemail.

For security, we have to stop picking up the phone

Featured Article

How a viral AI image catapulted a Mexican startup to a major adidas contract

Antonio Nuño, Fatima Alvarez, and Enrique Rodriguez have been friends since they were five years old. As teenagers, they became volunteers helping indigenous communities — first in Mexico, then in other countries — and saw that many of the women were artisans.  The trio came to realize that these artists…

How a viral AI image catapulted a Mexican startup to a major adidas contract

BDO, the auditor for Indian edtech startup Byju’s, has resigned with immediate effect, marking the second auditor departure for the embattled startup in about a year and further intensifying concerns…

Second Byju’s auditor exits in a year amid bankruptcy proceedings

A federal judge says he will deliver a punishment in Google’s antitrust case by August 2025, according to The New York Times, after ruling earlier this month that Google had…

Google to receive punishment for search monopoly by next August, says judge

ChatGPT, OpenAI’s text-generating AI chatbot, has taken the world by storm since its launch in November 2022. What started as a tool to hyper-charge productivity through writing essays and code…

ChatGPT: Everything you need to know about the AI-powered chatbot

The world will have to wait a little longer to see Blue Origin’s massive New Glenn rocket fly for the first time. That rocket had been scheduled to launch two…

The maiden voyage of Blue Origin’s massive new rocket won’t be for NASA

After 93 days on orbit, Starliner is coming home.  The spacecraft is a “go” for undocking from the International Space Station at 6:04 p.m. EST, though it will be leaving…

Watch live as Boeing and NASA attempt to bring empty Starliner back to Earth

Some of Vice President Kamala Harris’ wealthier donors are informally asking for FTC Chair Lina Khan to be replaced, reports Bloomberg. It’s not really surprising: Her expansive definition of antitrust…

Wealthy Harris donors are reportedly pressing for ouster of FTC Chair Lina Khan

Mangomint seeks to make it easier for spa and salon owners to run their businesses.

How a cold email to a VC helped salon software startup Mangomint raise $35M

The honors program is one of the first in the U.S. that allows incoming freshmen to apply for the program as part of their initial admission application.

University of Texas opens robotics program up to incoming freshmen

By using readily available natural gas as the feedstock, C-Zero hopes to produce emission-free hydrogen for less than other green hydrogen startups.

C-Zero is raising $18M to make emission-free hydrogen using natural gas, filings reveal

Meta on Friday published an update on how it plans to comply with the Digital Markets Act (DMA), the European law that aims to promote competition in digital marketplaces, where…

Meta will let third-party apps place calls to WhatsApp and Messenger users — in 2027

At the annual Roblox Developers Conference, the company announced on Friday a series of changes coming to the platform in the next few months and years. Most notably, Roblox is…

Roblox introduces new earning opportunities for creators, teases generative AI project

Apple is likely to unveil its iPhone 16 series of phones and maybe even some Apple Watches at its Glowtime event on September 9.

How to watch the iPhone 16 reveal during this year’s big Apple Event

Welcome to Startups Weekly — your weekly recap of everything you can’t miss from the world of startups. Want it in your inbox every Friday? Sign up here. You won’t…

Startups have to be clever when fighting larger rivals

The Philadelphia Eagles and the Green Bay Packers will face off tonight in their first game of the NFL season. But this season opener is a bit different. As the…

NFL kicks off in Brazil for the first time, but reporters and fans can’t post on X due to nationwide ban

Venture capitalist Tim Draper’s international pitch competition, “Meet the Drapers,” is partnering up with TikTok as it heads into its seventh season. Under the new tie-up, entrepreneurs will pitch their…

VC pitch show ‘Meet the Drapers’ partners with TikTok

It’s tempting to think the trend of EV startups merging with special purpose acquisition companies (SPACs) to go public has ended, seeing how many of them are struggling or defunct.…

Public EV startup with an indicted CEO is looking to raise an additional $100 million

In the world of modern AI, data is more than just a resource — it’s the fundamental core that aligns decision-makers, supports processes and enables innovation. As AI applications become…

The New Data Pipeline: Fivetran, DataStax and NEA are coming to TechCrunch Disrupt 2024

In a brief update ahead of the weekend, the London transport network said it has no evidence yet that customer data was compromised.

Transport for London outages drag into weekend after cyberattack

Meta-owned Instagram is jazzing up the inbox by adding new features for photo editing, sticker creation and themes. The company is trying to make Instagram more appealing as a messaging…

Instagram jazzes up its DMs with stickers, photo editing, and themes

Keep the excitement of TechCrunch Disrupt 2024 alive by hosting an exclusive Side Event after hours. Don’t miss out — today is the final day to apply for free! Maximize…

Last call: Boost your brand by hosting a Side Event at TechCrunch Disrupt 2024

Today’s your final chance to secure your TechCrunch Disrupt 2024 Student Pass with a $200 discount! Maximize your savings by opting for the Student 4+ Bundle and bring four or…

Students and recent grads: Last day to save on TechCrunch Disrupt 2024 Student Passes

The Equity podcast crew is wrapping up another eventful week, with real estate, AI agents, gambling and secondary markets — which are, of course, a form of legalized gambling. Mary…

Real estate revolutions and beanie baby economies

More antitrust woes for Google. The U.K’.s competition watchdog said on Friday that it suspects the company of adtech antitrust abuses. The tech giant will now have a chance to…

Google faces provisional antitrust charges in UK for ‘self-preferencing’ its ad exchange

You can build a reminder and task management system for yourself, and use a service that works for your team. But it might not be easy to get your family…

Karo is a to-do app that lets you assign tasks to your friends and family

Earlier this week, the EU’s lead privacy regulator ended its court proceeding related to how X processed user data to train its Grok AI chatbot, but the saga isn’t over…

Elon Musk’s X could still face sanctions for training Grok on Europeans’ data

Telegram has updated its website to explicitly allow users to report private chats to its moderators, the company said in its FAQ page, as it updated some of its other…

Telegram quietly updates website to allow abuse reports following founder’s arrest

SpaceX President Gwynne Shotwell made a public plea to one of Brazil’s top judicial figures on Thursday, asking him to “please stop harassing Starlink” amid the ongoing battle in the…

‘Stop harassing Starlink,’ SpaceX president tells Brazilian judge

OSOM always had a difficult road, with plans to launch a privacy-focused handset.

Osom is shutting down on Friday, as it had ‘no customers for a mobile phone’