Def Con 2023 White Hat Conference: hackers can use "cheap Bluetooth transmitter" to forge iOS notifications and then implement social worker fishing
CTOnews.com, August 17 (Xinhua) at the Def Con 2023 White Hat Conference, the White Hat Jae Bochs used a "cheap Bluetooth transmitter" to demonstrate "how to send false notifications for fishing" to technicians participating in the conference using Apple iOS's Bluetooth pop-up window.
It is reported that the Bluetooth transmitter consists of a raspberry pie, a Bluetooth adapter, several antennas and an external battery. Jae Bochs said the device, which costs about $70, allows hackers to use the device to conduct phishing attacks on personal Apple devices.
The demonstration of ▲ image source Jae Bochs in fact, the principle of Jae Bochs is roughly the same as the "Bluetooth pop-up window" of Huaqiangbei's "copycat AirPods". It is through mastering the method of calling Apple iOS "Bluetooth pop-up window", so as to realize the behavior of customizing "pop-up window content".
"if users interact with the fishing prompts that pop up on iPhone, they may be tricked into 'handing over their passwords'," Jae Bochs said.
Jae Bochs claims that Apple has been aware of the problem since 2019. However, Apple has not taken any action, mainly because "Apple has sold a large number of AirPods headphones, and if the agreement is changed, it will cost Apple a lot of money."