back
538 comments
Wow! Is the trick that we now have powerful microcomputers small enough to fit into a USB plug? That's pretty incredible technology. How many years ago did this become possible? My IT security training is dated, I am aware of the risks of plugging in a random USB key, but just a cable from a helpful "coworker"? Yikes.
It’s a copy of the NSA ANT Coppermouth cables. That was part of the Snowden leak, so it’s been possible since at least then (the doc itself is circa 2008) if you have a three-letter name and a national security black budget.

https://en.m.wikipedia.org/wiki/NSA_ANT_catalog

There is already an Arm Cortex M0+ in the end of every USB type C cable for power negotiation.

It has a complex codebase and firmware update methods to migrate to new USB specs. Cheap cables don't even support signing so go to town tampering with stock cables if you are so inclined.

Also an Attiny85 can fit inside just about anything.

My favorite BadUSB hello world is using the Arduino HID library to make a Digispark toggle caps lock randomly with maybe 10 lines of code. Drives people nuts.

In the leaks that happened around the time of Snowden's revelations, there were DVI/monitor cables that had transmitters that would broadcast the decrypted signal so that someone with the receiver nearby could "share" the screen. No software installed for security software to find. Just a cable that could be installed by the cleaning crew after hours.
That level of miniaturization is far older than Apple's removal of the iPhone headphone jack in 2016, but the related lightning-to-audio jack dongle had a microcontroller with a DAC inside that you'd never think existed due to the form factor.
> How many years ago did this become possible?

I don't know, but I do know that back in 2013 you could get an ARM computer running linux and a webserver with wifi and 16Gb storage in a space the size of an SD card. That is still a bit too big to fit inside a USB plug without being obvious, but not by much. https://hackaday.com/2013/08/12/hacking-transcend-wifi-sd-ca...

Fitting the electronics inside the usb plug itself has been used for years in slimline usb memory sticks and in tiny readers for micro-sd too.

I expect that this has been possible for nearly 10 years, but maybe just not commercially viable for consumers for most of that.

See also http://tomu.im/.
Not just the microcontroller but also the wifi radio and antenna... But a USB-A socket is pretty big anyway. This isn't too different from the tiny wireless mouse dongles that have been around for a few decades.
In 2008 we had USB flash drives which extended only two millimeters beyond the laptop when you plugged them in, and Wifi dongles in the same form factor.
On a similar note, as I understand it skimmers placed on ATM machines and the like are now so small they are almost impossible to detect.
See also:

C-to-C charger cables with Bluetooth remote activated dual payloads: https://sneaktechnology.com/product/usbninja-custom-type-c-t...

I easily modified mine to mimmic Apple Keyboard USB IDs to avoid notifications. Works great!

Cellular GPS tracking car charger: https://www.amazon.com/Charger-Locator-Professional-Listenin...

Cellular GPS tracking USB charger cable: https://www.ebay.com/itm/223990414124

I have been making, collecting, and testing toys like this for more than a decade.

It is a race to the bottom on price now.

Your best defense for USB code execution attacks is use Linux with USBGuard or QubesOS with the default USB quarantine VM.

Windows and Mac users are currently easy targets. I don't know of any good defenses there.

Who buys this stuff? Other things in the shop:

> Screen Crab: This covert inline screen grabber sits between HDMI devices - like a computer and monitor, or console and television - to quietly capture screenshots. Perfect for sysadmins, pentesters and anyone wanting to record what's on a screen.

> Shark Jack: This portable network attack tool is a pentesters best friend optimized for social engineering engagements and opportunistic wired network auditing. Out-of-the-box it's armed with an ultra fast nmap payload, providing quick and easy network reconnaissance.

> Key Croc: The Key Croc by Hak5 is a keylogger armed with pentest tools, remote access and payloads that trigger multi-vector attacks when chosen keywords are typed. It's the ultimate key-logging pentest implant.

They say "pentesters." What prevents a malicious actor from buying and using these tools?

I think I am missing something here.

I live in Seattle and have had my car broken into three times. Each time, they steal my iPhone's USB cable. I wonder, could they add cellular connectivity to this cable and use it as a GPS locator?
As an aside: somewhat ironic that a shop selling gear such as this has such a large 3rd-party javascript footprint. At least some of that js is required for the page to work, as I'm unable to see pictures of the device. I counted 25 3rd party domains in uMatrix. That's quite the attack surface.
I'm not sure what is scarier, the existence of this cable, or the amount of Javascript that this site tries to run when you visit it. According to my NoScript plugin, it's loading Javascript from at least 17 different domains.
Been a follower of Hak5 since way back in the day. Even crashed at the hak house with Darren a long time ago. Cool to see them here since they actually hack stuff haha.
After looking at that product page and seeing how something that looks innocuous can be so insidious, does anyone else wonder just a bit whether the page is not so innocent and visiting it may have been a mistake.
This makes me miss older, simpler protocols. Sure, a parallel cable could also be compromised to snoop but at least it couldn't pretend to be some other device or install rootkits.
When Apple inevitably removes all physical ports from some future iteration of iPhone, I wonder if they’ll use the existence of tech like this to market the change as a benefit to security.

I’m simultaneously impressed, curious and disturbed.

It was my firm belief that many of the angry mobs at vote counting offices around the 2020 elections were cover for planting these types of devices. That is very much out of the Roger Stone playbook. The lack of anomalies has shaken that belief… but I do hope that the existence of these types of devices is included in security training for future polling staff.
I want to need one of these things. Pranks on my friends are difficult with a lockdown and permanent wfh status, so I’d need a better reason. Can anyone think of non evil uses? My imagination is stunted I guess.
This is one reason I prefer good old 3.5mm audio jacks in my phone. I have no fear of putting any headphones or adapter in that port.
Yet another reaffirmation that physical access is game over.

"But the case is locked!" Are the peripherals? Even if the case connectors are locked away behind a bird-box/knockout, if someone left one of these dangling unplugged off of the keyboard, do you think your field technician won't unlock the box and plug it right back in?

Took me a moment to realise, but this is for keyboards, not iPhones. I don't think (?) anybody can access anything from an iPhone using an evil cable (using publicly-known attacks).
I would advise a trip to MG's own site that has a lot more technical information on the cable:

https://mg.lol/blog/

Its kind of cool to see someone I've been following for years and seeing the whole dev cycle of this product.

His exploding USB drive was pretty cool and came before this idea:

https://mg.lol/blog/mr-self-destruct/

The trick is, you can't buy this particular one because you just don't know what it does exactly.

I have tried to make a cable like that in the past be the best I got was to hide the electronics in what looked like a bead. Unfortunately, this only really works with USB-B devices where users are already used to having beads on the cable which for practical purposes limits attacks to printers and older scanners.

I remember about decades ago that keyloggers would be very scary and powerful because your only defense was your password, and you couldn't know someone was logging in at the same time as you if you were not aware of it.

Nowadays, with 2FA and all the big companies doing extra security check up when they see something wrong with the login patterns ... I don't see the use of keyloggers anymore.

Just visiting this created a Cart on my chrome new tab page for Hak 5. Must be a new feature on Google Chrome. Just FYI
Can somebody recommend good charging cables with the data lanes disabled? Would put my mind at ease when I'm traveling.
Reminds me of the 2013 blog post of Panic in which they discover the lightening to hdmi “adapter” was in fact a small computer performing transcoding to HDMI. It was much larger and bulkier than 0.mg, but another example of a hidden computer in a place where one might expect just some simple wires.

https://panic.com/blog/the-lightning-digital-av-adapter-surp...

These are normally made with something like an esp32 squeezed into the plug.

To exfiltrate data by WiFi, there is a neat way to get data out... Just have the esp32 connect to all unencrypted WiFi networks in turn and send the data out via a DNS tunnel.

Then the attacker can provide their own WiFi network, but it will also work with airplane WiFi, cafe WiFi, guest networks, etc.

And obviously with DNS tunnelling it works against WiFi networks that require a 'sign in' after connection, even without signing in.

I fantasize all the time about buying stuff like this and using it for nefarious purposes.

Unfortunately the only real legit use for it is boring security work.

The best way to use this while avoiding big legal trouble would be to stalk a single target that would never have any idea they are being stalked and doesn’t have much resources to come after you legally. Maybe an ex-girlfriend or something.

that opening line of needing a million dollar budget LOL if anyone follows @_MG_ you'll know that this has been a very long project thats really not been that expensive the dude dropped a load around defcon then hak5 came in and said hey we can charge and arm and a leg for these...
This is incredible.

I remember in the early days of the web getting a copy of the Anarchist Cookbook. One idea was to glue the phosphorus material from a match stick to the spinning portion of a floppy disk. Of course that was a n00b level hack.

We've come a long way since then...

Does it work like a normal USB Cable, so can you still charge your phone with it and connect it to the PC?

Couldn't find this information. If yes, you can just switch someones cable in his bag and attack him with that. We need to be very careful in the future with our cables...

I'd be more than a little nervous ordering one of these cables from a company that its sole job is creating spyware. If they're okay with spying on their customers' customers why wouldn't they spy on just their customers too?
I feel like there are some clever uses for this that aren't even security related.
The product description does a really poor job of explaining what this is to someone who has never heard of it. It's just a wink-wink-nudge-nudge reference to some DEFCON talk.

Can someone explain what this is? Is it a hardware keylogger?

You should use a data blocker when using an unknown USB cable to charge your phone. Occasionally described as a USB condom.

Simply a Male to Female USB adaptor with the data wires not passed through.

I don't get what these can be used for. Is the idea to swap it out with your victim's iPhone charging cable and use it to exfiltrate photos and stuff from the iPhone?
One thing cables are good at is being long enough to act as great antenna. It makes sense the wifi range is 2KM.
> "self destruct" features that involve wiping the onboard flash memory

Had an entirely different image in mind.

Not sure why the data industrial complex is net yet giving cables for free around malls, schools, etc.
Other than state against state actors what are legitimate use cases for this type of spying?
Can you write custom code for this thing? I actually have some non-nefarious use cases...
We can't even trust our own cables. How do we combat this type of attack vector?
Scary that this is available to almost anyone now!