Hackers Bypass Network Perimeters by Mailing Exploits Direct to Targets
IBM security researchers reveal a technique called "warshipping" where attackers build cheap, cellular-connected devices and mail them to targets to infiltrate corporate Wi-Fi networks from the inside.
IBM security researchers expose a technique known as "warshipping" that allows hackers to bypass external network defenses by mailing cheap, low-power exploit devices directly to a target company. Instead of searching for software vulnerabilities or guessing passwords remotely, attackers simply hide a small, custom-built computer inside a package and let the postal service deliver it straight to the mail room.
The proof-of-concept device costs about one hundred dollars to build and contains a cellular modem and a wireless chip. Once the package arrives at the target location, the attacker uses the 3G connection to remotely activate the device and scan for nearby corporate Wi-Fi networks.
The hidden hardware silently captures the wireless handshake data from nearby employee devices and sends this scrambled information back to the attacker's servers. Powerful computers then crack the Wi-Fi password, granting the hacker full access to the internal corporate network to steal sensitive data without ever setting foot on the premises.