nerdexam
EC-Council

312-50V12 · Question #312

Kate dropped her phone and subsequently encountered an issue with the phone's internal speaker. Thus, she is using the phone's loudspeaker for phone calls and other activities. Bob, an attacker…

The correct answer is C. Spearphone attack. The scenario describes a Spearphone attack, where an attacker exploits a phone's hardware, specifically its sensors, to reconstruct audio from loudspeaker vibrations to breach speech privacy.

Submitted by lucia.co· Mar 4, 2026Wireless Network, Mobile, IoT, and OT Hacking

Question

Kate dropped her phone and subsequently encountered an issue with the phone's internal speaker. Thus, she is using the phone's loudspeaker for phone calls and other activities. Bob, an attacker, takes advantage of this vulnerability and secretly exploits the hardware of Kate's phone so that he can monitor the loudspeaker's output from data sources such as voice assistants, multimedia messages, and audio files by using a malicious app to breach speech privacy. What is the type of attack Bob performed on Kate in the above scenario?

Options

  • ASIM card attack
  • BaLTEr attack
  • CSpearphone attack
  • DMan-in-the-disk attack

How the community answered

(61 responses)
  • A
    15% (9)
  • B
    3% (2)
  • C
    74% (45)
  • D
    8% (5)

Why each option

The scenario describes a Spearphone attack, where an attacker exploits a phone's hardware, specifically its sensors, to reconstruct audio from loudspeaker vibrations to breach speech privacy.

ASIM card attack

A SIM card attack targets the Subscriber Identity Module for identity theft, network access manipulation, or unauthorized charges, not the phone's physical audio output hardware.

BaLTEr attack

An aLTEr attack is a network-level attack that intercepts and manipulates LTE data traffic, focusing on cellular communication, not directly exploiting local phone hardware for audio monitoring.

CSpearphone attackCorrect

A Spearphone attack leverages a smartphone's internal accelerometers or gyroscopes as side-channels to capture subtle vibrations produced by the device's loudspeaker. By analyzing these vibrations, an attacker can reconstruct the audio output from the loudspeaker, thus monitoring voice assistants, calls on loudspeaker, and multimedia playback without accessing the microphone, directly matching the described exploit.

DMan-in-the-disk attack

A Man-in-the-disk attack involves an attacker gaining unauthorized access to the phone's storage to tamper with, steal, or inject data, not exploiting sensors to reconstruct loudspeaker audio.

Concept tested: Mobile device side-channel attacks via hardware sensors

Topics

#mobile hacking#acoustic side-channel attack#Spearphone attack#privacy breach

Community Discussion

No community discussion yet for this question.

Full 312-50V12 Practice