Reversing effects of remote hacking using flipper

Hi, hopefully someone here can help.

Please note that I’m a disabled 45 year old man with severe sensory PTSD, agoraphobia, social anxiety and psychogenic hyperventilation that lives in Oxfordshire, UK. A motability car and ten rental vehciles have been hacked remotely by several people who have a hate fuelled vendetta against disabled people.

We met at a gym in 2017 but are not connected and there’s no contact. They come up as people to follow on instagram but there’s no contact. In February '23 they indicated that hacking attacks were imminent and would be ongoing.

They’ve hacked 15 TVs using a remote device or programme. The frequency is adjusted so the sound is tinny, hollow and distorted. It’s often so bad that symptoms of psychogenic hyperventilation are induced - namely, inability to draw deep breath, tremor, crying out to relieve pain, tightening chest and oblique, rising blood pressure and acute nausea.

Each TV was replaced under warranty but still they continue.

Since 12/11/22 they’ve hacked the vehicle systems of my motability and ten rental/dealer demos. Once the hack is applied the vehicle becomes wayward, shudders over bumps, has poor body control and rolls a lot more. There’s also excessive vibration through pedals and steering and mpg is 10-30 down. No dealers can reverse the effects of the hack even with system resets.

I’m already severely disabled. This unrelenting hacking is causing an excruciating state of fight or flight that’s akin to psychological and physical torture.

Can flipper be used to reverse the effects they apply to the car and TV?

It’s definitelty happening and I’m not imagining it or exaggerating. With the car hack it was most recently applied on 12 May, removed on 14 and then re-applied on 18 so it can be reversed.

Perhaps you’re aware of what they’re using?

If an expert or someone that understands the technology well can respond it would be much appreciated. It’s imperative that I can resume control over technology again which is only possible if there’s a device available to stop/reverse what they’re doing.

Yours sincerely,

Josh Ross

The vehicle issues don’t sound like any kind of remote electronic hack. If someone messed with the vehicles it’s almost certainly physical in nature. I can say with confidence the Flipper isn’t the correct tool. At best the Flipper could be used as a less helpful version of the diagnostic tools the dealer used. The Flipper could be used to factory reset a TV but the remote that came with it would work just as well. I recommend you talk about this with someone you trust locally that may be able to help. From what I see described here you don’t need a hacker or hacking tool. You need a proper mechanic to look over the vehicle.

1 Like

Firstly, thank you for responding. I’m absolutely certain that the hacks are remote but don’t know the names of the devices or programmes used. That’s why I’ve reached out to the Flipper Zero community. After looking at many online videos it seems that flipper can be used to adjust the sound frequency of a TV once it’s recognised the frequency of the TV. The adjustment appears to be in sub ghz>frequency analyser. As Flipper can also be used to open cars surely there must be a way to use it to reverse the effects of their hack? The car has been reset by main VW dealers and an independent and the symptoms still remain. Please can someone here that knows flipper zero well advise if vehicle handling can be adjusted in one of the sub menus? As you’ll have read the hacking is worsening an already gruelling life; compounding symptoms of severe PTSD, agoraphobia, social anxiety and psychogenic hyperventilation. Even if people here don’t know what devices are hacking the TVs and cars, could you use a psychic sixth sense to identify them? I’ve scoured the internet for guidance on what devices but am no closer to knowing.

2 Likes

The flipper can’t do this in one way or the other.

The Flipper can change the channel or the volume of a TV. If the remote is known it can copy every signal and can do what the original remote can do.
But what you are describing for 15 TV needs physical access to the system. I would go one step further and say it can’t be done without any seen changes on the TV.
And if this is true, you should not replace the TV with 15 identical, this should be very limited to one specific device. More variation limit the possibility of repeat this attack.

The second issue is some kind of car. Normally this devices got a control box, that separates every function from each other. Else a malfunction in the light could fire the airbag or hit the brakes … at least if you want to have it licensed for public use.
So you need here also physical access to change anything on the system. From what you are describing, it sound s like some kind of extension (liquid, sugar, …) in the tank or the oil. Not necessarily a ‘digital hack’. Depending on the used motor.

Maybe someone here is TV and radio electrician, but the chances to reach a car mechanic are lower.
From my limited knowledge about this systems, this can’t be done remotely with a Laptop from the street nearby. Even if you are motivated enough to compromise this facility.

1 Like

The chance of anyone with a FZ or likewise devices changing the flash seems really unlikely, the flipper does have a extension board you could use for SPI flashing and other things like that , but also the attacker would have to get physical acces to accomplish this in most cases.

Also the chance of re-flashing the vehicles wireless seems unlikely, also vibration and other things while driving sound more like a physical problem rather then a software/hack caused problem.

Maybe it is more coincidental you have bad luck of the vehicle breaking and needing replacements next to being vulnarble to some things that are still unrelated to these problems? I have been jerking around with my car on odb2/can bus etc and have not managed to cause permanent problems even while trying it seems to be reversable every time , but i guess the mechanics already checked the flash of it and it is just physical problems after being finding out the remote part is also not that secure? Not saying i doubt your experience, but I am wondering about options that could be a problem, but the chance someone reflashed your vehicle with diffrent content is very-very unlikely over the air.

1 Like

Thank you for taking the time to respond. I appreciate that the hacking sounds unlikely but it’s definitely happening and isn’t imagined. It’s perpetrated by a criminal and friends with an anti-disability vendetta that live in Hertfordshire, UK which is 70 miles and 1 hour 30 minutes from where I live in Faringdon, Oxfordshire. I’m desperate for it to end and am open to all solutions. The attacker doesn’t and never has had physical access to the devices they’re manipulating. They’re probably not using a flipper zero which is ‘range sensitive’. The vehicle problems aren’t hardware related and weren’t resolved with a scan and reset. Let’s approach it from a different angle please. Can those who know flipper well see if there is a sub menu or function that can adjust TV frequency and alter car ride/handling any aspect of the car’s dynamic profile? Users would likely need to explore unfamiliar sub menus and/or plug in options to find out. Please do so if possible. I would buy the device and use it to reverse the effects of the criminal hacks if it does have those uses. Please also advise if a plug in board/extension is needed for those uses. Flipper zero seems to have many sub functions to control home entertainment devices and unlock/deactivate doors/lights. I’m simply desperate to the reverse the effects of the hacks applied to the TV and car. Surely it can also control sound frequency and vehicle dynamics? Please note that it isn’t coincidence or bad luck. The criminals have also applied the ride/handling hack to 10 dealer demo/loan/rentals that were provided while dealers attempted to sort the motability car. The criminals probably aren’t using flipper zero to apply their hacks and certainly aren’t in range. It’s been reported many times but no action is taken. As you can imagine it’s worsening the very severe disabilities - sensory PTSD, agoraphobia, social anxiety and psychogenic hyperventilation. I’ve also considered approaching ‘access control’ experts. The car hack has manipulated the control units and sensors and it would seem merely to be a ‘switch’ or ‘function’ on the criminals’ remote hacking device. When it’s applied, as it is now, the car shudders, wallows, has poor body control and rolls a lot. The other hack also reduces mpg by 10-30 by applying excessive noise, vibration and harshness through pedals, steering and seat. Please try to approach it from a different angle and help if possible.

This is exactly what I wrote.
You’d think it is any kind of ‘remote hack’ and I try to tell you it is more unlikely than you think.
You need a CCTV and officials (police). Not a bunch of hobby enthusiasts, who will analyze protocols for fun.

What you are describing is altering an embedded device at firmware level. This ist not the topic of a flipper.
Here we are trying to capture and replaying remote control signals of various ways.
At some time the Flipper Zero also add Arduino Microprocessor features (advertised during the Kickstarter campaign), but even than it is not the tool to alter firmwares.

The nearest at your idea is @jmr with bruteforce the FireTV, to find ‘hidden function’. But even here in the worst case the device will go to factory reset. No altering at the firmware will happens.
And this very cool project is not even close to what you are thinking is happening.

The most criminal activity you will find here is ‘Card Cloning’ via NFC/RFID. Because of curiosity and only a few will have private access to a NFC/RFID reader, they will try to get company access. Again, no altering of any system or firmware. Just emulating.

I have a little idea how a TV is working. And I have no idea how you want to force any TV to play a signal as you are describing. Without physical access.
If we are talking of white noise (no signal, known from the old days as broadcasts stopped in the late hours, or between 2 signals) and this is a problem at your facility, you maybe should not use TV in the first place. This is not a malfunction.
Let the TV forget the programming is possible remote (factory reset), but easily recoverable. In this case I come back to CCTV/Police as solution.

Now I do want to know more, can you tell me more about the mobility car and features/options it has? For the TV , if it has RF remote or using DVB-T trough the air, it could be noise/jammed, and if you have a annoying neighbor, it could be replayed ease since most have no encryption.

If you do not want to post to many details, also feel free to spam me in DM, or strip them to techinical specs only.

A lot of old protocols are still used in to many devices, so i kinda wonder about the technical specifications. I do not need specific key details etc, just specs/made/model on stuff to read up into hardware spec.

And if people really want to bother people with disabilities for fun, i think there are many people that would want to help you get them caught , cause this is unethical beyond reasoning.

I really wonder how and what they could permanently break over the air, now i kinda wanna know…

p.s , not trying to sound comforting but I also have my “diagnoses” so that might be the reason why i am not replying on a hourly base and vanish for a couple of days here and there , but if people would really bother you because , it also triggers my evil radar and i want to retaliate. So I want to know what could be done to mitigate the problems for you.

1 Like

We will all find ourselves in a vulnerable situation at some point. It’s very easy to empathize. Do on to others as you want them to do on to you so of course we would love to help if we can. I’d be happy to take this to a personal chat as well if it’s more comfortable for the OP. I have had others come to me in PM with sensitive issues. We must enjoy the process of helping or we would not spend so much time here. Nothing would make me happier then resolving this issues.

2 Likes

Since some people are interested in this topic, regardless of the circumstances of this question, the main rules do apply also here.

We need

  • Vendor of the device(es)
  • Model
  • Version

It always helps to know what happen when (relative timeline, not absolute dates).
Best described in what you expect to happen and what is happening. Sounds sometimes silly, but you are experience something, we don’t. Your eyes, ears, … are the only that could describe the situation. Our picture is drawn from your text. Sometimes it is a Mona Lisa, sometimes a picasso. Your picture is at the moment something a 3 years old can scribble.

You can’t just hack every TV and a Car, just because you are a skilled hacker. Maybe especially this used device has a know issue, and I am wrong the whole time.
In any case, keep going on in generalisation won’t help either of us.

1 Like

Do these people have any named group? Are you the only person experiencing this, or are there other disabled people nearby that are experiencing the same thing?
I would consider letting the authorities in your area know as well, they are going to be able to physically intervene better than most of the people on this forum.

Thank you for reverting back and caring. All constructive comments are welcomed as I’m desperate to bring this torrid situation to an end.

It’s definitely not the neighbour or anyone local that’s hacking the TVs and cars.

The perpetrators are with absolute certainty based in Watford, Herts. and the surrounding areas. It’s 70 miles/90 minute drive from where I live in Faringdon, Oxfordshire. 15 TVs have been hacked so far. They are different models/brands from John Lewis (Uk department store).

It’s clearly nothing to do with the brand or model as each one has been afflicted with the same sound hack.

Using a remote device the perpetrators adjust the frequency of the sound. When it’s switched above a certail level on their device it’s hollow, tinny and distorted. On occasion they also manipulate the picture so it flashes, pixelates, gets lines of varying width across the screen or so channels don’t load.

Symptoms of the disabilities are quickly induced so the only option is to suffer immeasurably and sit it out or switch the TV off. As mentioned I’m severely disabled with sensory PTSD, agoraphobia, social anxiety and psychogenic hyperventilation. Symptoms: inability to draw deep breath, laboured breath, crying out to relieve pain, nausea, tremor, slowed cognition, confusion, fight or flight syndrome, nightmares, flashbacks, avoiding/leaving busy or small spaces. The perpetrators are aware of the severe disabilities and that they’re caused by historic and ongoing crime as well as triggers.

There’s been considerable research done on what they’re using and how it’s done. There are several ‘Wired’ Magazine articles which confirm that altering tech device. sound frequency remotely is possible. They don’t detail what device can do it so I’m intending to follow up with those sources. Other ethical hackers also describe software that can alter vehicle dynamics remotely. Most are available to contact via email only and haven’t responded yet.

The car hack alters a mode/setting within a control unit/ecu. When applied, which it has been since 18 May the car wallows, shudders over bumps, is listless and there’s a lot more roll than usual. They also manipulate another unit/sensor so there’s excessive vibration through pedals and steering and the mpg is 10-30 down. They first activated the car hack on 12/11/22 and I didn’t receive the car back from the dealer till 15/1/23. The perpetrators likely switched the mode off during that period as dealers don’t appear to know how to sort it. As I don’t know how to deactivate what the perpetrators have applied it’s not possible to tell dealers how to resolve it. A basic system reset doesn’t work so what else can be suggested?

The motability car is a 2021 mk8 Golf GTD. On several forums CAN invader (Control Area Network) has been mentioned as has Kvaser, Peak, EMS Wunsche and USB2 Can. I’m no expert in access security control and don’t know what the devices do. The same ride/handling and noise/vibration/harshness hack was also applied to 11 other dealer demo/courtesy/rentals. Namely, 4 mk8 VW Golfs, 2 Mk4 Ford Focuses, 2 current shape Kia Ceeds, 1 Kia X-Ceed, 1 Ford Puma, 1 Seat Arona.

The hacked TVs. 1st hack applied from 28/1/23 causing set to switch itself on and off constantly. Sound hacks began on 25/2/23:

  • 1 Samsung QE43Q65A (2021 model year)
  • 1 Samsung UE43BU8500 (2022)
  • 1 LG 43UQ91006LA (2022)
  • 1 Sony Bravia KD43X72K (2022)
  • 1 LG 50Nano766QA (2022)
  • 2 Samsung QE43Q65B (2022)
  • 3 Samsung QE50Q80B (2022)
  • 1 Samsung QE43QN90B (2022)
  • 1 LG OLED48A26LA (2022)
  • 1 Panasonic TX-32M330B (2023) - non smart TV. Connected via aerial and within one minute they’d manipulated the sound on this too
  • 1 Toshiba 4k 43 UF3D53DB (2022)
  • 1 Linsar 4k GT43UHDLuxe - current set

Is there an expert that lives near (ish) or is prepared to travel? Perhaps you could visit or I could come to you? If the problems can be solved I’m willing to pay a sum + cover travel expenses within reason. It would seem that perhaps Flipper Zero can alter TV sound frequency and vehicle dynamics? Without guidance I wouldn’t know how to reverse the effects of the perpetrator imposed hacks.

Yours sincerely

Josh Ross

16 cyber crime/action fraud reports and six police reports have been submitted. No action has been taken yet.

All the while I’m suffering with TVs whose sound is manipulated to excruciating frequencies remotely and a motability car whose ride/handling has dropped from 3/3.5 out 5 to 1 out of 5 because of the vehicle hacks.

The TV sound hacking began on 25/2/23 and car hacking on 12/11/22. It’s destabilising every aspect of life and negatively impacting relationships with friends and family.

Recently a care organisation and family member contacted local MPs. They’ve been asked to discuss the seriousness of the situation with Herts Police (where the perpetrators live), Met Police (where Mum lives) and Thames Valley Police (my local police force). In the interim the effects of the hacks must be reversed as it’s pushing life into an unrelenting state of disarray.

The description makes me think it is ‘just’ a physical tap on antenna/power lines, and not a typical software hack. May be wrong.

For the TV’s i would start at vendors site, get the firmware binaries , put them on USB and reflash the TV to get it back to normal states, meanwhile swap to cabled connections and not use wifi, to make sure the connections are good, even better, try the tv offline with firmware from vendor’s site.

You can sorta jtag into the utp and trigger menus on a lot of tv’s to manage service settings even if the display is broken physcally, so confirming configurations and firmware should be a good start to see where the ploblem occurs, maybe some codecs got crippled and cause weird stuff.

Also make sure you do not use WPS options on your wireless network cause it is to easy to break.

For the golf mk8 on the other hand i am really wondering about the stuff, not driving a VAG car, but I am familiar with jerking around on the CAN bus, just i did not manage to do things like this over the air, breaking configurations on em3something and CAN is not that hard, but doing this over the air is another story, i could think about some potential vulnerabilities that could be triggerd using compromised USB devices in your car.

If it’s a car within factory waranty and you do have subscriptions to mapupdates etc, it could be like other car mades that you can login to the manufactures site, register you dash, and get maintenance updates without the dealership free or cheap, that you can install fairly easy by just extracting a zip to USB and boot it on car dash. My car also has some update features that do change more software updates then just the navigation system, and some Japanese car vendors even use LUA script to update their devices, so it is very easy to home-brew on these navigation/dash integrations. Just personally I am not that experienced with VAG cars since my last euro car was about 10 years ago and they are also using vcds? or something like that instead of regular odb2/can/em3xxx but also not that hard to get tools needed to go deep into your own car.

For the TV part i can explain some risks that exist, and could be causing problems even if a neighbor a block away has a slow repeater on the same bandwidth that just replays raw without thinking like pre loranet stuff, could create a lot of random weird problems like this for the entire block. but also these devices should be easy to track down, cause they tend to create a lot of noise also on the frequencies they work at, so just following the noise with a directional antenna could make you find the source of trash. there is even a hobby called foxhunting for people who do this for fun, find a transmitting beacon in the middle of nowhere.

But i would split the TV/CAR issues into separate topics to be sure, cause also some newer TV’s use shitty rf remotes that can be replayed and so also create a lot of user errors. The car on the other hand, does need some more physical interaction, doing this remote without compromised devices connected to it are not that easy to accomplish.

For the TV part , definitely first steps should be using a formatted usb stick , preferable in fat32 so it has no crippled ntfs features and reflash them with binaries from vendor sites, try older and newer ones to see differences. A broken codec could also be fixed by this. And disabling insecure wifi configurations like WPS etc are always a good idea.

The car, especially since its a mark8, does trigger my interests more, im from across the channel, so it is not that i do not want to help, but it would be a multiple day detour to take the tunnel or take a ferry or fly over, so hoping you have some more local options, I am gonna visit my personal cardealership anyways next week, and they also have a proper cartech geek working, i will ask him for fun if he heard anything about these cars, and knows potential ways to make sure it is factory default without weird configs, and if there is a easy way to check if your ecu flash is still as it should be.

p.s

I did find this file , that confirms there are some potential risk factors but also confirm that you would need wifi access already, or have compromised the local devices like USB