Could an attacker control a device without physically possessing it?¶
Yes. Remote access, compromised accounts, cloud management and malware can let an attacker control a device that remains in someone else's home, office or pocket. Ownership, physical possession and authorship of digital activity are different propositions.
Remote control can use desktop services, support or RMM tools, web interfaces, remote commands or stolen sessions. Automation can also produce activity without anyone controlling the device interactively at that moment.
Opportunity to unlock, approve, connect or interact with the device locally.
Whether the relevant digital activity was performed locally, remotely, automatically or through a compromised account.
Test who or what operated the device¶
Look for remote-access installations and configuration, historical sessions, authentication, network connections, process activity, commands and screen-control records. Device and cloud logs may reveal a controller even where the owner reports no physical handover.
Compare the timing with local activity. Screen locks, local input, device movement and the owner's communications or location can support or challenge the proposition that they were personally operating it.
Physical possession remains relevant. It may provide opportunity to unlock the device, approve a prompt or install a tool. Remote access also does not exclude local involvement: a local user may cooperate with, knowingly assist or be deceived by the remote operator.
Keep four identities separate¶
An investigation may need to distinguish:
- the owner of the device;
- the person physically possessing it;
- the account or technical session performing an action; and
- the person personally directing that action.
Evidence can answer one of these without resolving the others. Reporting should therefore state the supported layer precisely. A remote-session record may rebut a simple possession-based inference, but it does not automatically establish who the alternative controller was.
Key takeaway
Do not equate possession with use: test remote access and automation, then report device ownership, location, session activity and personal control as separate findings.