PSA: Don't buy any thermal imaging products from AGM Global Vision.
Nearly all of their thermal imaging scopes and binoculars are continuously broadcasting a 2.4 GHz WiFi carrier. This is a marketed feature for "connecting to their smartphone app" but is a blatant safety risk. Not only is the intended function of it insecure, in a threat aware environment you may as well be strapping loudspeaker to yourself. Signals often travel farther than they should especially when you don't want them to.
Every single last one of their products contains an onboard WiFi module. This includes product lines like the Rattler, Clarion, and Taipan devices. I'm going through the list of their products and I don't think there is a single one that
doesn't have a built-in RF transceiver. While this seems to be a trend for digital optics, AGM is a particularly bad offender.
RACLV36 (Rattler V2):
The RF Transceiver chip here is a
RTL8189ES-VB-CG. It never turns off. Even if you desoldered this completely you now no longer have a functioning board. Desoldering the WiFi antenna also wouldn't be sufficient to prevent unintentional RF leakage.
AGM ReachIR LRF 35-640
SHCR2308001714AT | AGM Secutor LRF 50-384
SHCR2308001712AT | AGM Taipan TM10-256i
Same RF module as the Rattler product line.
If you're wondering WTF this may even be for in a thermal rifle scope, the marketing description is for their smartphone app "
AGM Connect" (
archive)
If you thought the literal hardware backdoor was bad, the the app itself is collecting your:
- Mobile phone model, browser type, IMEI, operating system version
- Hardware address
- Software version
- IP address
- Network access mode/type
- Operation logs
- Location-related information
When I have some free time I will be unpacking the firmware blob for the devices themselves to see what else is going on. Unsuprisingly, the app itself (a Chromium wrapper) is the spawn of the botnet and tries to phone home every 5 seconds.
Don't buy any digital optic that has a RF device in it. It will get you killed. It has already gotten people killed.
thx