34C3: Microphone Bugs

Inspiration can come from many places. When [Veronica Valeros] and [Sebastian Garcia] from the MatesLab Hackerspace in Argentina learned that it took [Ai Weiwei] four years to discover his home had been bugged, they decided to have a closer look into some standard audio surveillance devices. Feeling there’s a shortage of research on the subject inside the community, they took matters in their own hands, and presented the outcome in their Spy vs. Spy: A modern study of microphone bugs operation and detection talk at 34C3. You can find the slides here, and their white paper here.

Focusing their research primarily on FM radio transmitter devices, [Veronica] and [Sebastian] start off with some historical examples, and the development of such devices — nowadays available off-the-shelf for little money. While these devices may be shrugged off as a relic of Soviet era spy fiction and tools of analog times, the easy availability and usage still keeps them relevant today. They conclude their research with a game of Hide and Seek as real life experiment, using regular store-bought transmitters.

An undertaking like this would not be complete without the RTL-SDR dongle, so [Sebastian] developed the Salamandra Spy Microphone Detection Tool as alternative for ready-made detection devices. Using the dongle’s power levels, Salamandra detects and locates the presence of potential transmitters, keeping track of all findings. If you’re interested in some of the earliest and most technologically fascinating covert listening devices, there is no better example than Theremin’s bug.

32 thoughts on “34C3: Microphone Bugs

    1. I think it’s not exactly mentioned in their whitepaper, but basically in the talk they’ve discussed the trade-offs of spyware. Points I remember:
      – many ways of infecting are harder to control (e.g. you can’t predict if or when someone would open your exploited data, that leads to infection with your spyware)
      – spyware won’t always be stationary
      – traces of spyware not always as easy to remove as physical bugs
      – probably some more, that I’ve just forgot…

      In my opinion, the real lesson is to create more awareness on surveillance and that physical bugs are probably less uncommon, than we might expect.

      1. I think he means taking one of those tiny “prison butt-plug phones”*, removing the speaker and modifying the firmware to auto-answer (or just changing a setting to auto-answer).

        *you know the ones marketed as a “Bluetooth earpiece and phone in one” things that are shaped and targeted towards convicted criminals world wide.

        What is missing in the video is that the GSM bug, although would only last 2 hours on batteries… if wired into the mains (AKA “the charger”) behind a plug socket or switch, then it should last theoretically indefinitely, or until either the battery epic-fails or an electrolyte dries out.

      First off… read after the HaD article under the advertisement, before the thought or comments regarding the article. The comment section is explicitly titled, with the number of thoughts preceding, "THOUGHTS ON "34C3: MICROPHONE BUGS""

This is the same WordPress I'm guessing format for all the articles.

      This is the same WordPress I’m guessing format for all the articles. I’ve dealt with bugs, electronic surveillance, technical surveillance and more advanced electronic warfare related weapons since the U.S. President Clinton administration. I’ve also worked performing AR&D and Quality Systems classical and alternate related methods development as well as the whole systems development life cycle (SDLC) for basically hardware, software, documentation, methods, training and up to site plant master validation plans. I’ve done corrective action and preventative action investigations as well as out of specification investigations in regulated industry with the DHHS, DOJ and DHS potentially over my shoulder or working with me even training them in some systems.

      Then I got thrown out into the World of more DOJ & DHS civil servant on down knightmare not well disclosed systems and am trying to advocate awareness about the article and other issues that are more advanced alternate methods and systems that do in fact exist in a more “non official use” capacity and need to be disclosed to the public.

      For instance… would you want a sniper shooting at you whenever they want with lasers, masers, or you name it remote sensing & transmission tech that can go undetected if not one tries to learn about what is to be detected???

      Therefore, I have plenty of thoughts I like to share. That is all. What do you do to contribute?

