logo

Machine-in-the-Middle (MitM) BLE Attack

ID: 818333a9-d661-5d4d-908e-70b5817ee3dd

STIX ID: report--818333a9-d661-5d4d-908e-70b5817ee3dd

Feed Name: Black Hills Infosec Blog

Threat Score
60/100

Date Published: 2020-10-28

Date Updated: 2026-04-27

Author: BHIS

...
...

This report demonstrates a practical BLE relay (Man-in-the-Middle) attack against a KeyWe smart lock using two Raspberry Pi 3B+ devices, Kinivo BTD-400 adapters, Node.js tools (noble, bleno, gattacker), and simple commands to spoof the lock's BLE advertisement and proxy traffic; the author documents setup, commands, captured GATT traffic, and notes the attack's applicability to other BLE smart locks and the risk posed by auto-unlock features.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.