Could an attacker control a device without physically possessing it?¶
Yes. An attacker can control a device without ever physically possessing it.
Avoid the dangerous assumption¶
The dangerous assumption is that activity on a device was performed by the person who owned, held or was near it.
Remote control may occur through:
- remote desktop
- support software
- RMM tools
- malware
- web interfaces
- cloud management
- stolen sessions
- remote command execution
- compromised accounts.
The device may remain in the victim’s home, office or pocket while another person operates it from elsewhere.
Investigators should examine:
- remote-access software
- active and historical sessions
- network connections
- account and device logs
- process activity
- commands
- screen-control records
- malware
- configuration changes
- user reports.
Physical possession still matters. It may affect opportunity, access to stored information and the ability to approve prompts or unlock the device.
But possession alone is not proof of authorship.
Likewise, remote access does not exclude local involvement. A local user may have installed the tool, approved the session or worked with the remote operator.
Keep four questions separate:
- who owned the device
- who physically possessed it
- which account or session acted
- who personally controlled the activity.
The evidence may answer one without answering the others.
Where remote control is plausible, compare the timing with the owner’s movements, communications and device use. That may support or challenge the suggestion that the owner was personally operating the device.
Remote access may therefore create reasonable alternative explanations for investigators.
Operational takeaway¶
Do not equate device possession with device use; test whether remote access, automation or another controller could explain the activity.