Why Mobile Was the Soft Target
The customer detected and mitigated binaries dropped on endpoints within 10 minutes. Shippโs team pivoted to the one area not covered: mobile. Developers used personal phones for MFA testing. BYOD was rampant. The team conducted passive surveillance to learn pattern-of-life details: coffee shop visits, leaving times. No van kidnapping. Just observation and Bluetooth attack planning.
Bluetooth Jamming and Masquerade
Teslaโs service manuals are public. One Bluetooth module sits under the front badge, one under the rear. Shipp used an M5Stack Cardputer ($25) with an nRF24 dongle to jam those modules. Another Cardputer or flipper zero masqueraded as the car. The victim, unable to connect to their Tesla for Spotify, paired with the attackerโs device. Total hardware cost: $95. The demo used a flipper for the nicer UI.
Payload Drop and Persistent Access
Once paired, the flipper ran a USB rubber ducky script over Bluetooth. The payload executed automatically on the Android device โ a Metasploit reverse shell. Android 16 kills outbound app connections after five minutes. Shipp used that window to set SELinux permissive, install Termux via ADB, and open a reverse SSH tunnel through an AWS listener. They then ran shell commands to remove the screen lock and dismiss keyguard. The device remained accessible until rebooted.
Lateral Movement and Lessons Learned
With persistent remote access, the team used Scrappy (screen copy) for full remote desktop, then sock proxy and BloodHound to enumerate the Windows domain. They reused passwords and found keys that shouldnโt have been on the phone. The attack required no clever tricks. Total cost: $25 for the Android developer account plus $100 in hardware. The customer implemented mobile monitoring and a BYOD policy update.
Q&A
What recommendations did you give the customer? Push mobile logging into XDR, implement a BYOD policy, and treat phones as an attack vector on the risk register. โถ 19:52
How did you pivot without Windows credentials on the phone? Reuse of passwords found on the device, combined with sock proxy for enumeration. โถ 21:33
Did the developerโs phone already have root? Yes, we targeted them because they were a developer with root. Getting root on modern Android is too time-consuming otherwise. โถ 23:27
Did you find secrets on the phone you can talk about? Iโve never not found something a developer wasnโt supposed to have. Keys, personal data โ the big takeaway is separate development phones. โถ 27:13
Notable Quotes
budget is not a blocker. Like I said, this is really really low hanging fruits. Tim Shipp ยท โถ 18:36
Iโve never not found anything a developer wasnโt supposed to have on any of their devices. Tim Shipp ยท โถ 27:22
It doesnโt need to be clever or pretty to work. Tim Shipp ยท โถ 18:34
Key Takeaways
- A $125 attack using a cardputer and Android developer account can compromise a corporate network.
- Developers with personal rooted phones and BYOD are a critical blind spot in most security programs.
- Persistent access is achievable by chaining Metasploit, ADB, and Termux before Android kills outbound connections.
About the Speaker(s)
Tim Shipp is CTO and Co-Founder of ThreatLight, an agentic incident response platform. He has built and led IR and red teams for over 20 years, served as a Major in the British Army Cyber Reserves, and conducted approximately 200 incident response investigations.