Close Menu

    Subscribe to Updates

    Get the latest news from tastytech.

    What's Hot

    Trump pardons former US Congress member accused of insider trading | Donald Trump News

    June 7, 2026

    How a USB-connected speaker can infect a PC without ever being touched

    June 7, 2026

    Stellar Blade Blood Rain Trailer Reveal Is Raising AI Alarm Bells

    June 6, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    tastytech.intastytech.in
    Subscribe
    • AI News & Trends
    • Tech News
    • AI Tools
    • Business & Startups
    • Guides & Tutorials
    • Tech Reviews
    • Automobiles
    • Gaming
    • movies
    tastytech.intastytech.in
    Home»Tech Reviews»How a USB-connected speaker can infect a PC without ever being touched
    How a USB-connected speaker can infect a PC without ever being touched
    Tech Reviews

    How a USB-connected speaker can infect a PC without ever being touched

    gvfx00@gmail.comBy gvfx00@gmail.comJune 7, 2026No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email


    After successfully replacing the firmware with a replacement image that did nothing more than display the word “patched” on the speaker’s LED display, the researcher got to wondering what else a hacker might do. So he turned his attention to FreeRTOS, the open source operating system that ran the Katana V2X. It contained a set of HID functions for allowing the speaker to act as a human interface device, a classification that includes keyboards, mice, and webcams. The speaker implemented a limited HID that allowed for things like changing the volume and playing or pausing sound, but little else.

    The researcher discovered that he could change the speaker’s USB descriptor set, which is essentially a report that informs devices about the capabilities of a USB- or Bluetooth-connected peripheral. He was able to augment the existing descriptor set with a second one that reported the speaker being a keyboard. Then he used code already included in the firmware to streamline the process of sending keypresses.

    All of this gave Moorats an idea: What if he used his device to send commands to the speaker that used the HID to pass them along to the connected PC? After some trial and error, he found that he could. In a blog post published on Wednesday, he wrote:

    Chaining it all together, I was able to totally remotely, over the air, upload a custom firmware to my speaker which I hadn’t paired with, which would reboot, flash the custom firmware, and after rebooting type in the command echo pwned and execute it.



    In a real attack scenario, I would execute the keystrokes for opening powershell.exe or similar and paste an actually malicious one-liner into that, but as a proof of concept, this was more than enough for me. A real attacker would also likely disable the routine for updating the firmware in both normal and recovery mode, making it impossible to wipe the malicious firmware from the device or patch it in the future.

    This is worsened by the fact that Bluetooth is always on for the speaker, even in sleep mode, with no apparent way to disable it.

    Before the speaker and USB-connected device can interact, they must successfully complete a challenge-and-response authentication procedure. Since the devices perform this handshake automatically each time the software boots, this isn’t usually a problem for the hacker. In certain cases, however, such as when the Katana V2X app isn’t open on the connected device, it’s a requirement.

    Table of Contents

    Toggle
      • Related posts:
    • One Moment Changes Everything in This Holiday Classic Streaming on Hulu
    • Christmas Eve Gaming Crushed as Steam Goes Offline
    • Websites have a new way to spy on visitors: Analyzing their SSD activity

    Related posts:

    AI models can acquire backdoors from surprisingly few malicious documents

    File System vs. Partition: Popular Digital Storage 100% Explained

    Apple will finally start building Mac mini computers in the U.S., significantly reshaping desktop, w...

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleStellar Blade Blood Rain Trailer Reveal Is Raising AI Alarm Bells
    Next Article Trump pardons former US Congress member accused of insider trading | Donald Trump News
    gvfx00@gmail.com
    • Website

    Related Posts

    Tech Reviews

    US States Are Reportedly Planning To Sue To Block Paramount’s Warner Bros. Takeover

    June 6, 2026
    Tech Reviews

    Baseus Bowie MC2 Clip-On Earbuds Review: For $60, I’m Impressed

    June 6, 2026
    Tech Reviews

    Star City’s most intriguing character doesn’t even have a name — as Apple TV star reveals role in new sci-fi series is like ‘playing a living ghost’

    June 6, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025185 Views

    Every Clue That Tony Stark Was Always Doctor Doom

    October 20, 2025113 Views

    We let ChatGPT judge impossible superhero debates — here’s how it ruled

    December 31, 202592 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from tastytech.

    About Us
    About Us

    TastyTech.in brings you the latest AI, tech news, cybersecurity tips, and gadget insights all in one place. Stay informed, stay secure, and stay ahead with us!

    Most Popular

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025185 Views

    Every Clue That Tony Stark Was Always Doctor Doom

    October 20, 2025113 Views

    We let ChatGPT judge impossible superhero debates — here’s how it ruled

    December 31, 202592 Views

    Subscribe to Updates

    Get the latest news from tastytech.

    Facebook X (Twitter) Instagram Pinterest
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 TastyTech. Designed by TastyTech.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.