Researchers at the University of California, Irvine, have demonstrated a novel side-channel attack called Mic-E-Mouse, which leverages the high-performance optical sensors in modern computer mice to eavesdrop on nearby conversations. The attack exploits the extreme sensitivity of these sensors, which can reach up to 20,000 dots per inch (DPI), allowing them to detect minute vibrations on a desk surface caused by sound waves from human speech. By capturing these subtle vibrations, the mouse can effectively act as a makeshift microphone, even though it was never designed for audio input. The research team developed a sophisticated pipeline that combines advanced signal processing and machine learning to filter out background noise and reconstruct intelligible speech from the raw movement data collected by the mouse. In their experiments, the researchers achieved a speech recognition accuracy of up to 61% using a standard $35 optical mouse, demonstrating that the attack is feasible with inexpensive, widely available hardware. The process resulted in a significant improvement in signal quality, with up to +19 dB gain, making the reconstructed audio much clearer. This attack is classified as a side-channel attack because it gathers information through an unintended physical pathway, rather than exploiting software vulnerabilities or network weaknesses. Traditional security measures such as antivirus software and firewalls are largely ineffective against this type of threat, as the attack relies on physical properties of the hardware and does not necessarily leave traces in system logs or trigger conventional security alerts. However, the attack does require the installation of specialized software on the target computer to collect and transmit the mouse sensor data, which could potentially be detected by security tools. The need to exfiltrate data from the compromised system also increases the risk of detection by network monitoring solutions. The researchers published their findings on arXiv and highlighted the broader implications for hardware security, emphasizing that even trusted peripherals like computer mice can become vectors for sophisticated espionage. The discovery underscores the importance of considering physical and side-channel threats in security assessments, especially in environments where sensitive conversations occur near computers. While the attack is currently a proof of concept, it raises concerns about the potential for real-world exploitation, particularly in high-security settings. Organizations are advised to be aware of such unconventional attack vectors and to monitor for suspicious software that could facilitate side-channel data collection. The research also suggests that future hardware designs may need to account for such risks to prevent similar vulnerabilities.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Security researchers disclosed a new attack dubbed Mic-E-Mouse showing that some computer mice can be repurposed to capture nearby conversations. The reporting indicates the attack turns mouse hardware into an unintended listening device, raising concerns about covert audio surveillance through common peripherals.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
malwarebytes.com
Open sourcecsoonline.com
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.