Florian Bausch writes on the ERNW Insinuator of analysing some laptops last year for possible espionage. The devices had been given to employees to work at home during Covid-19.
The reason was that he feared the company could have been victim of industrial espionage. Starting in spring 2020, the IT help desk got several employee laptops with full hard drives, caused by a huge amount of audio recordings. The audio files contained recordings even of highly sensitive telephone conferences. An automated scan on all employee computers for such audio recordings showed that about 300 devices were affected.
The audio driver used on this laptop obviously does not check the return value of the RegQueryValue call and therefore seems to default to a debug mode, which causes the audio driver to write recordings to disk as soon as some program accesses the microphone.
All this trouble with full hard drives was indirectly caused by the Corona pandemic. Until 2019 the customer never experienced this issue, although the audio driver was the same. However, starting in early spring of 2020, the customer sent the employees home. Work from home now was the new standard mode of operation and people needed to communicate. They did this using softphones on their laptops. Before Corona they worked on-site and used desk phones.
Read more in the article here.
Image credit: by Chris Yang on Unsplash