Researcher Makes Legit-Looking iPhone Lightning Cables That Will Hijack Your Computer

A researcher known as MG has modified Lightning cables with extra components to let him remotely connect to the computers that the cables are connected to. “It looks like a legitimate cable and works just like one. Not even your computer will notice a difference. Until I, as an attacker, wirelessly take control of the cable,” MG said. Motherboard reports: One idea is to take this malicious tool, dubbed O.MG Cable, and swap it for a target’s legitimate one. MG suggested you may even give the malicious version as a gift to the target — the cables even come with some of the correct little pieces of packaging holding them together. MG typed in the IP address of the fake cable on his own phone’s browser, and was presented with a list of options, such as opening a terminal on my Mac. From here, a hacker can run all sorts of tools on the victim’s computer.

The cable comes with various payloads, or scripts and commands that an attacker can run on the victim’s machine. A hacker can also remotely “kill” the USB implant, hopefully hiding some evidence of its use or existence. MG made the cables by hand, painstakingly modifying real Apple cables to include the implant. “In the end, I was able to create 100 percent of the implant in my kitchen and then integrate it into a cable. And these prototypes at Def con were mostly done the same way,” he said. MG did point to other researchers who worked on the implant and graphical user interface. He is selling the cables for $200 each.

