Researchers show it’s possible to load malware onto switched off phones
When your smartphone is off it isn't and that means certain active components can be hacked even when you think they can't.
Key takeaways
- With the latest iOS, it’s possible to locate your iPhone even if it’s powered off.
- The researchers said in their research paper, posted last week to the arXiv preprint server, that they were able to show that it’s possible install malware on the Bluetooth chip.
- The researchers wrote in the paper that they disclosed the issues they found to Apple, and the company did not have any feedback.
Cite or link to this article
Griffin, M. (2022) 'Researchers show it’s possible to load malware onto switched off phones', 311 Institute, 17 May. Available at: https://www.311institute.com/researchers-show-its-possible-to-load-malware-onto-switched-off-phones/ (Accessed: 1 October 2026).
With the latest iOS, it’s possible to locate your iPhone even if it’s powered off. That’s because even when the iPhone is turned off, certain wireless chips remain on, allowing the phone to still send signals that can help locate it.
Now, a group of researchers from the Technical University of Darmstadt in Germany has found that one of those chips, the one that enables Bluetooth, can be exploited and hacked to install malware on the phone - even when it’s turned off.
The researchers said in their research paper, posted last week to the arXiv preprint server, that they were able to show that it’s possible install malware on the Bluetooth chip. It’s important to note, though, that this research is at this point mostly theoretical and there’s no evidence that this kind of attack has been used in the wild. Also, as the researchers point out in the paper, hackers would need to first hack and jailbreak the iPhone to be able to access the Bluetooth chip and exploit it, potentially making it a bit redundant in most cases.
Still, even for hackers who have already taken control of the phone, hacking the Bluetooth chip would give them access to another place to collect data, an especially useful one because it’s available even when the phone is powered off.
“[Low-Power Mode] is a relevant attack surface that has to be considered by high-value targets such as journalists, or that can be weaponized to build wireless malware operating on shutdown iPhones,” the paper read.
The researchers explain in the paper that the Bluetooth chip, as well as other wireless chips - those that run Near Field Communication or NFC, which is used for Apple Pay, for example, and Ultra-wideband (UWB) which is used along with Bluetooth to turn the iPhone into a car key - keep running when the phone is off in what the researchers call Low-Power Mode, noting that it “is different from the energy saving mode indicated by a yellow battery icon.”
The researchers conclude that Apple’s implementation of this Low-Power Mode ultimately enhances the security of users because it allows them to find a lost or stolen phone even if it’s turned off. But because the wireless chips are still on, they also pose a new threat model.
The researchers wrote in the paper that they disclosed the issues they found to Apple, and the company did not have any feedback. Apple declined to comment, and the researchers did not respond to a request for comment.
Ryan Duff, a security researcher who has experience with iOS, told Motherboard recently that the attack described in the paper would be useful as an add-on to an existing malware implant “but it's not really a standalone attack without additional vulnerabilities and exploits.” That’s because the researchers did not show that it’s possible to hack the Bluetooth chip on its own and then jump from there and hack the phone.
“It may be possible to exploit the Bluetooth chip directly and modify the firmware but the researchers did not do that and there isn't a known exploit that would currently allow that,” Duff, who is the director of cyber products at cybersecurity firm SIXGEN, told Motherboard in an online chat after reviewing the research paper. “The same applies from jumping from the Bluetooth to the phone. It would require an additional exploit.”
Still, the researchers’ findings show an attack that could have real-life applications.
“It's something running after the phone is off, which could be useful,” Ryan added. “Network connectivity is not part of it though so whatever is collected would only be accessible to an attacker after power-on.”
FAQ
Why does this matter?
When your smartphone is off it isn't and that means certain active components can be hacked even when you think they can't.

About the author
Matthew Griffin Founder, 311 Institute
Matthew Griffin is a multi-award winning Futurist and expert in Disruption and Innovation, Geopolitics, Leadership, and Technology, who NASA have described as a "walking encyclopaedia of the future" and a "futurist Polymath."
Read full bio
Matthew Griffin is a multi-award winning Futurist and expert in Disruption and Innovation, Geopolitics, Leadership, and Technology, who NASA have described as a "walking encyclopaedia of the future" and a "futurist Polymath." 15-time best selling author of the "Codex of the Future" series, Matthew is the Founder and Futurist in Chief of the 311 Institute, a global Futures and Deep Futures advisory firm working with royal households, world leaders, G7, G20, and G77 governments, NGOs, and multi-national mid and mega cap firms to help them explore, shape, and lead the next 50 years of business and society.
An award-winning YouTube creator with over a million followers, with an unrivalled global reach and impact, Matthew is a highly sought-after international keynote speaker, lecturer, and mentor who collaborates with global leaders through the United Nations Alliance of Civilizations (UNAOC) and United Nations General Assembly (UNGA) to shape pivotal initiatives such as the UN’s AI for Humanity program, the United Nations Conference of the Parties (UN COP), and the World Economic Forum in Davos.
As the former Global Head of Cloud, National Security, and Enterprise Sales for companies including Atos, Dell-EMC, and IBM, Matthew has a proven track record of building multi-billion dollar business units and turning failing divisions into market leaders. His ability to identify, analyse, and communicate the implications of hundreds of emerging technologies and trends is unparalleled, and his insights are trusted by many of the world’s most respected organisations, including ABB, Accenture, Adidas, AON, ARM, BCG, Centrica, Citi, Coca-Cola, Dentons, Deloitte, Dow Jones, EY, Google, KPMG, Lego, Legal & General, LinkedIn, Microsoft, PepsiCo, Qualcomm, RWE, Samsung, Siemens AG and Siemens Energy, T-Mobile, UBS, VISA, Walmart, Workday, Worldpay and many others.
Regularly featured in the global media including the AP, BBC, Bloomberg, CNBC, Discovery, Forbes, Khaleej Times, Telegraph, TIME, ViacomCBS, WIRED, and the WSJ, Matthews mission is to help organisations create a fair and sustainable future whose benefits are shared by everyone irrespective of their ability, background, or circumstances.
What future do you need to see?
Choose one to get started on security and privacy and the future of your organisation.
Sources and further reading
- it’s possible to locate your iPhone even if it’s powered off theverge.com
- Technical University of Darmstadt tu-darmstadt.de
- said in their research paper, arxiv.org
- which is used for Apple Pay support.apple.com
- to turn the iPhone into a car key support.apple.com
- SIXGEN sixgen.io
Source: first published by the 311 Institute on 17 May 2022. Cite as: Griffin, M. (2022). Researchers show it’s possible to load malware onto switched off phones. 311 Institute. https://www.311institute.com/researchers-show-its-possible-to-load-malware-onto-switched-off-phones/
You are welcome to quote this article with credit and a link to the original.