AirHopper: Bridging the Air-Gap between Isolated Networks and Mobile Phones using Radio Frequencies Mordechai Guri1, Gabi Kedma1, Assaf Kachlon1, Yuval Elovici1,2 1Department of Information Systems Engineering, Ben-Gurion University 2Telekom Innovation Laboratories at Ben-Gurion University {gurim, gabik, assafka}@post.bgu.ac.il,
[email protected] Abstract innovative and persistent attacker will eventually find a way to breach the network, to eavesdrop, and to Information is the most critical asset of modern transmit sensitive data outward. organizations, and accordingly coveted by adversaries. Accordingly, when a network is used to deliver When highly sensitive data is involved, an organization highly sensitive data, or to connect computers that may resort to air-gap isolation, in which there is no store or process such data, the so called 'air gap' networking connection between the inner network and approach is often applied. In an air-gapped network, the external world. While infiltrating an air-gapped there is no physical networking connection (wired or network has been proven feasible in recent years (e.g., wireless) with the external world, either directly or Stuxnet), data exfiltration from an air-gapped network indirectly through another, less secure network. is still considered to be one of the most challenging Nevertheless, employees may carry their mobile phases of an advanced cyber-attack. phones around the organization's workplace, possibly In this paper we present "AirHopper", a bifurcated within the vicinity of a classified computer which is malware that bridges the air-gap between an isolated part of an air-gapped network. This may occur despite network and nearby infected mobile phones using FM reasonable security procedures, and does not require signals.