3.3 Trojan Programs in Mobile Communication Systems
229
3.3.2 A “Bug” in a Smartphone Component Is Another
Opportunity for a Spy
Mobile phone users who trust service centers for repair of their devices can also
became victims of cyberespionage. As of the moment of publication of the book, it
is only a theoretical possibility shown by information security specialists; however,
theory in this case can easily become practice (if it hasn’t happened already). Media
are yet to report about users of mobile devices who have found bugs in their phones
after repair. Perhaps the sole reason is that these devices are properly hidden.
The report on the work done [12] published by the hacker group can cause mild
(or not-so-mild) paranoia in many owners of mobile devices. But the possibility of
tapping is not a surprise—this is not exactly a difficult task. Both Android users and
owners of advanced iOS-based devices can become victims of cyberespionage.
In addition to publication of documentation, the authors of this research also
reported about their study during the conference in 2017, Usenix Workshop on Offensive Technologies. The main problem is that phones fresh out of the factory are more
or less reliable. Most companies are pretty good at controlling production cycles at
their plants; therefore, intrusion of a third party with the purpose of installing bugs
is hardly probable, if not impossible. However, after a phone or a tablet leaves the
production plant, its safety cannot be controlled.
In this case, the user who broke the screen of his device and contacted a repair
company may become a victim of unscrupulous repair service employees. Here is
what the researchers from the Ben-Gurion University in Negev have to say: “The
hazard of installation of malicious software inside consumer devices shall not be
received with incredulity. As our document shows, attacks using such software are
absolutely real, scalable and invisible for most existing inspection technologies. A
motivated intruder is able to perform large-scale attacks or aim efforts at a specific
target. Hardware architects need to consider the possibility of protection of spare
mobile phone parts.”
As an example, researchers used a usual touchscreen equipped with a built-in
chip, which helped intercept data transmitted from the screen to the common bus
and vice versa. This technique was called chip-in-the-middle. Such attack allows not
only to intercept, but also to modify the data described above.
The chip installed by researches was equipped with special software, which
allowed for a wide range of actions aimed at the user device. For example, the
modified touchscreen was capable of registering device unlocking passwords; the
camera could take photos (without any visible signs of action) of everything in front
of the lens and send the photos to the intruder on condition of presence of an Internet
connection.
The most interesting part is that this intrusion does not require extremely complex
chips: they can be designed by any good specialist in electronics and produced by any
Chinese plants. Chinese merchants, after all, don’t care much about what orders they
get; hardly anyone is going to investigate it (except for Chinese special services).
229
3.3.2 A “Bug” in a Smartphone Component Is Another
Opportunity for a Spy
Mobile phone users who trust service centers for repair of their devices can also
became victims of cyberespionage. As of the moment of publication of the book, it
is only a theoretical possibility shown by information security specialists; however,
theory in this case can easily become practice (if it hasn’t happened already). Media
are yet to report about users of mobile devices who have found bugs in their phones
after repair. Perhaps the sole reason is that these devices are properly hidden.
The report on the work done [12] published by the hacker group can cause mild
(or not-so-mild) paranoia in many owners of mobile devices. But the possibility of
tapping is not a surprise—this is not exactly a difficult task. Both Android users and
owners of advanced iOS-based devices can become victims of cyberespionage.
In addition to publication of documentation, the authors of this research also
reported about their study during the conference in 2017, Usenix Workshop on Offensive Technologies. The main problem is that phones fresh out of the factory are more
or less reliable. Most companies are pretty good at controlling production cycles at
their plants; therefore, intrusion of a third party with the purpose of installing bugs
is hardly probable, if not impossible. However, after a phone or a tablet leaves the
production plant, its safety cannot be controlled.
In this case, the user who broke the screen of his device and contacted a repair
company may become a victim of unscrupulous repair service employees. Here is
what the researchers from the Ben-Gurion University in Negev have to say: “The
hazard of installation of malicious software inside consumer devices shall not be
received with incredulity. As our document shows, attacks using such software are
absolutely real, scalable and invisible for most existing inspection technologies. A
motivated intruder is able to perform large-scale attacks or aim efforts at a specific
target. Hardware architects need to consider the possibility of protection of spare
mobile phone parts.”
As an example, researchers used a usual touchscreen equipped with a built-in
chip, which helped intercept data transmitted from the screen to the common bus
and vice versa. This technique was called chip-in-the-middle. Such attack allows not
only to intercept, but also to modify the data described above.
The chip installed by researches was equipped with special software, which
allowed for a wide range of actions aimed at the user device. For example, the
modified touchscreen was capable of registering device unlocking passwords; the
camera could take photos (without any visible signs of action) of everything in front
of the lens and send the photos to the intruder on condition of presence of an Internet
connection.
The most interesting part is that this intrusion does not require extremely complex
chips: they can be designed by any good specialist in electronics and produced by any
Chinese plants. Chinese merchants, after all, don’t care much about what orders they
get; hardly anyone is going to investigate it (except for Chinese special services).
