AirHopper: Bridging the Air-Gap between Isolated Networks and Mobile Phones using Radio Frequencies
Information is the most critical asset of modern organizations, and\naccordingly coveted by adversaries. When highly sensitive data is involved, an\norganization may resort to air-gap isolation, in which there is no networking\nconnection between the inner network and the external world. While infiltrating\nan air-gapped network has been proven feasible in recent years (e.g., Stuxnet),\ndata exfiltration from an air-gapped network is still considered to be one of\nthe most challenging phases of an advanced cyber-attack. In this paper we\npresent "AirHopper", a bifurcated malware that bridges the air-gap between an\nisolated network and nearby infected mobile phones using FM signals. While it\nis known that software can intentionally create radio emissions from a video\ndisplay unit, this is the first time that mobile phones are considered in an\nattack model as the intended receivers of maliciously crafted radio signals. We\nexamine the attack model and its limitations, and discuss implementation\nconsiderations such as stealth and modulation methods. Finally, we evaluate\nAirHopper and demonstrate how textual and binary data can be exfiltrated from\nphysically isolated computer to mobile phones at a distance of 1-7 meters, with\neffective bandwidth of 13-60 Bps (Bytes per second).\n