Categories: HackingSecurity

Mactans charger, a malicious hardware that could infect any Apple iOS devices

Mactans charger, this is the name of the malicious charger that will be presented by researchers at the Black Hat 2013 conference in July that is able to inoculate a malware in any Apple iOS devices.

Researchers from the Georgia Institute of Technology  announced the creation of Mactans charger, a custom wall charger for Apple iPhone and iPad that is able to inoculate a malware in any devices running any version of iOS.

The infection of device is possible through a chargers called Mactans that is based on BeagleBoard architecture. The BeagleBoard is a low-power open-source hardware single-board computer designed by Texas Instruments in association with Digi-Key that is sold to the public under the Creative Commons share-alike license.

An introduction of their presentation states that they will be able to demonstrate how an iOS device can be infected in less than a minute after plugging in a malicious charger.

“In this presentation, we demonstrate how an iOS device can be compromised within one minute of being plugged into a malicious charger. We first examine Apple’s existing security mechanisms to protect against arbitrary software installation, then describe how USB capabilities can be leveraged to bypass these defense mechanisms. To ensure persistence of the resulting infection, we show how an attacker can hide their software in the same way Apple hides its own built-in applications.”

The name Mactans derive by  is a highly venomous species of spider in the genus Latrodectus, the researchers Billy Lau, Yeongjin Jang, and Chengyu Song will present their creation at the Black Hat 2013 conference in July.

It’s not the first time we read about hardware disguised as everyday objects that are used to spy on networks, let’s remind the various researches promoted by DARPA that led to the design of objects able to penetrate the host network. This time Mactans charger is a circuit used to infect mobile users.

Once installed the malicious code with Mactans charger the researcher are also able to hide it exactly in the same way Apple does with its own built-in applications, the infection is possible due the exploit of a vulnerability already disclosed to Apple but that the company hasn’t yet fixed.

Apple in fact hasn’t yet  recognized the findings of the team, but the consequences of similar exploits are clear, potentially any iPhone or iPad could be compromised using its USB connection.

The researcher declared:

“The results were alarming: despite the plethora of defense mechanisms in iOS, we successfully injected arbitrary software into current-generation Apple devices running the latest operating system (OS) software. All users are affected, as our approach requires neither a jailbroken device nor user interaction.”

A last consideration relates to the possible impairment  of the supply chain of any hardware device and the need of hardware qualification… have you got an idea of what can be done exploiting the networks in our homes with compromised hardware.

Pierluigi Paganini

(Security Affairs – Hacking , Mactans charger )

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

MITRE revealed that nation-state actors breached its systems via Ivanti zero-days

The MITRE Corporation revealed that a nation-state actor compromised its systems in January 2024 by…

6 hours ago

FBI chief says China is preparing to attack US critical infrastructure

China-linked threat actors are preparing cyber attacks against U.S. critical infrastructure warned FBI Director Christopher…

18 hours ago

United Nations Development Programme (UNDP) investigates data breach

The United Nations Development Programme (UNDP) has initiated an investigation into an alleged ransomware attack…

21 hours ago

FIN7 targeted a large U.S. carmaker with phishing attacks

BlackBerry reported that the financially motivated group FIN7 targeted the IT department of a large…

1 day ago

Law enforcement operation dismantled phishing-as-a-service platform LabHost

An international law enforcement operation led to the disruption of the prominent phishing-as-a-service platform LabHost.…

2 days ago

Previously unknown Kapeka backdoor linked to Russian Sandworm APT

Russia-linked APT Sandworm employed a previously undocumented backdoor called Kapeka in attacks against Eastern Europe since…

2 days ago

This website uses cookies.