Research Centre

[Pass The SALT 2018] Are there Spectre-based malware on your Android smartphone?

Are there malware based on Spectre? Are smartphones vulnerable to Spectre? That's what this talk answers.


The Spectre attack has had massive coverage. This talk is not yet another explanation of Spectre, nor generic advice of what to do. Rather, this talk is oriented on implementation issues and answering 2 simple questions (which haven’t been addressed yet to my knowledge):

1. Is your Android smartphone vulnerable to Spectre or not? ARM has published a security advisory with a list of vulnerable processors. We’ll see that the answer isn’t as simple as checking the list. . .

2. How can we detect malware using Spectre, and are there any?



References

  • Pass The SALT: https://2018.pass-the-salt.org/schedule/#spectre

    Video: https://passthesalt.ubicast.tv/videos/are-there-spectre-based-malware-on-your-android-smartphone/

    Paper:  https://www.virusbulletin.com/uploads/pdf/magazine/2018/201807-Spectre-malware.pdf