- Academic researchers found a way to transmit confidential data from Airpago systems
- It implies having malware installed on the computer and an intelligent clock that accompanies it
- The attack is quite difficult to achieve
Security experts claim to have found a way to steal confidential data of Airpago systems using smart watches.
Computers with an airpago are physically isolated from the wider Internet, and cannot be accessed remotely. In general, they are used in high security and critical infrastructure environments, to protect confidential data and various operations.
University researchers led by Mordechai Guri, a specialist in the field of undercover attack channels, discovered a method that allows threat actors to exfiltrate login credentials, encryption keys or keyboard strokes.
Listening to secrets
The method, which they called ‘smartatck’, comes with enough warnings, but in theory, sees a threat actor who finds a way to physically access the target computer, or have someone (an unsuspecting or discontent employee) access and implement a piece of malware.
That malware will act first as an Infoptealer, collecting valuable information for exfiltration. Then, you will use the computer speakers to emit ultrasonic sounds, inaudible to the human ear, for the environment.
The sounds would reproduce at two frequencies: 18.5 kHz and 19.5 kHz. These two form the binary system, being the first zero, and the second, the one.
The last step is that the clock collects the sounds. You also need to have a special application installed, so you must compromise or should be used by the attacker.
If that did not seem difficult enough, the clock must face the speakers and should be placed in a range between 6 and 9 meters of the speakers. The data transmission rate also varies between 5 PB and 50 PBs, depending on the distance.
There are different ways to avoid intelligent attacks in Airpapped systems, prevent people from using smart watches, eliminating computer speakers. Sound Jammers could also work.
Through Bleepingcomputer