Def Con developer sells $200 Mac-hacking iPhone cables

They take around four hours to make and only 10-20% were actually good enough to sell

Apple Lightning cable

A Def Con attendee has developed a malicious iPhone cable that allows attackers to remotely execute commands on a victim's device and was selling it to anyone who could find him.

The cable itself looks like any other iPhone Lightning cable: white, regular length, charges the phone and prompts iTunes to open whenever it connects to a computer but has an embedded wireless module that allows hackers to control a Mac computer connected to the cable from afar.

The developer, going by the alias MG, said that an attacker could launch a command or malicious payload through a specially crafted app from within a 300ft vicinity of the target. This could theoretically increase to a limitless range if the attacker configured the cable to act as a client to a nearby network if it supported an external internet connection.

Selling for $200, the cable has made the news previously when it was first created but this is the first time it's gone on sale. The potential implications of its distribution could be disastrous, especially in the business world.

Advertisement - Article continues below
Advertisement - Article continues below

Imagine a scenario where a person posing as a prospective job candidate enters the office building for an interview, but accidentally leaves the cable behind, only for an opportunistic employee to take it for themselves at the end of the day after realising the cable has no owner.

The employee could then come to work the next day and charge their phone as normal using their Mac, leaving the entire company's network vulnerable to remote attacks - a big reward for a relatively small $200 investment.

These types of attacks aren't out of the ordinary, in December 2018 it was revealed that eight European banks were targeted by criminals who stole millions after planting rogue Raspberry Pi devices in meeting rooms.

"It's likely something that will be limited to very targeted attacks, such as swapping out a CEO's legitimate cable with a fake one," said Javvad Malik, security awareness advocate at KnowBe4. "One could conceive this being placed in a public place, such as an airport charging station, but it's probably easier for willing attackers to compromise public WiFi connections by setting up their own rogue hotspots.

"It may not be possible for the average person to tell whether a cable has been modified, so when in doubt, or when travelling, it may be worth using a 'USB condom' which, when used, blocks any data transfer, and only allows charging of a device." 

MG said on his blog that the cables "are hand built, and take ~4hrs to make" but he only lets around 10-20% of the cables he makes go out for sale after an extensive testing period.

Advertisement - Article continues below

According to MG, people that bought the cable at the Las Vegas security conference received "the cable, a bonus physical programmer (if you brick the device or use self destruct), access to the private early access group, and a 50% off discount code that can be used when the production cable goes live on Hak5".

MG added that the poor yield from his efforts "should be solved by moving this into manufacturing" but he noted there wasn't enough time to solve that before Def Con.

This year's annual security conference wasn't in short supply of weird and wonderful security news. Yesterday IT Pro reported that researchers had devised a way to remotely inject ransomware into DSLR cameras - a previously unknown attack vector that could be particularly harmful to tourists.

Featured Resources

What you need to know about migrating to SAP S/4HANA

Factors to assess how and when to begin migration

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

Testing for compliance just became easier

How you can use technology to ensure compliance in your organisation

Download now

Best practices for implementing security awareness training

How to develop a security awareness programme that will actually change behaviour

Download now


internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

data governance

Brexit security talks under threat after UK accused of illegally copying Schengen data

10 Jan 2020
Microsoft Windows

What to do if you're still running Windows 7

14 Jan 2020

Dell XPS 13 (New 9300) hands-on review: Chasing perfection

14 Jan 2020
operating systems

17 Windows 10 problems - and how to fix them

13 Jan 2020