BlackHat USA 2026 training
Bluetooth Low Energy Hacking Masterclass
This intensive two-day training provides a deep dive into Bluetooth Low Energy security, equipping cybersecurity professionals with advanced skills and a toolset to identify, analyze, and exploit vulnerabilities in BLE devices.
The training is predominantly hands-on, centered around practical work with a custom-designed Bluetooth training device called “BMO”. Equipped with a small display and control buttons, the BMO can emulate various BLE devices, behaving on the Bluetooth layer exactly like real ones - even allowing connections with official apps.
The session begins with the foundational exploration on how this technology works by interacting with the “BMO” training device: understanding BLE broadcasting (advertising device presence, trackers, beacons) and connections (services, characteristics, GATT). You will quickly turn on your simulated “lightbulb,” and surprisingly, you will already be able to take control over so many devices that do not implement any security mechanisms at all. We will start with phone‑based recon and attacks, then proceed to short scripts that control and simulate devices with only a few commands.
With this fundamental step complete, we will move on to passive interception of BLE communication, beginning with radio-layer sniffing. In addition, we will explore an unexpected yet highly effective alternative for analyzing app traffic: capturing Bluetooth packets directly on the phone. Thanks to the special configuration of the provided Android device, you will be able to view all the packets reliably live in Wireshark - without relying on external hardware or repeating captures.
We will follow with more complex topics: setting up a wireless remote relay/machine-in-the-middle scenario, identifying and cracking insecure pairing configurations, and analyzing BLE proprietary communication protocols.
With this arsenal of attacks mastered, you will confidently proceed to conduct your first security assessment of a BLE device: a remotely controlled car (simulated in the “BMO”). You will intercept communication, analyze the packets, attempt to replay, identify weaknesses in encryption, reverse-engineer, and attack vendor-specific command protocol. Once you succeed with this task, you can optionally follow up with the next level assessment: a “perfect security” smart lock!
In addition to the multi-device simulations in the “BMO” training firmware, participants with sufficient time can test the security of the provided real-world devices, such as smart locks, keyboards, and banking tokens.
Accompanying topics will also cover, among others, introduction to Bluetooth 5 and 6, Bluetooth Mesh, overview of BLE related vulnerabilities (from protocol specification to implementations), jamming, injecting and hijacking existing connections, firmware over the air, and device development/flashing (including adjusting our dedicated “BMO” training firmware).
If you haven’t reached Bluetooth overload by this point, the additional homework options will help you refine and expand your skills using the provided hardware kit and detailed step-by-step instructions.
Key takeaways
- Solid understanding of Bluetooth Low Energy, possible attacks, current tools, associated risks.
- Ready to use stable lab setup, allowing not only to revisit all hands-on exercises after the session, but also apply the skills directly to real devices.
- Ability to perform security assessment of a typical BLE device.
Who should take this course
- Pentesters, security professionals, red teamers, researchers.
- BLE device designers, developers.
- Anyone interested in BLE security.
Audience skill level
Beginner/intermediate
Student requirements
- No prior Bluetooth knowledge needed.
- Basic familiarity with Linux command line, python scripting, pentesting experience (mobile app security, Wireshark, …) will be an advantage, but are not required.
What students should bring
- Laptop (Windows, Linux or MacOS x86-64 or Arm Apple Silicon) capable of running virtual machine, 40GB disk space, 2x USB type A port (or USB hub), 5GHz wifi. Administrative privileges may be required to allow connecting external USB devices to VM (some corporate laptops may have this feature disabled).
- Optionally a smartphone, preferably Android (not necessarily latest, up to ~8 years old). Several Android phones will be available for students during the session. Moreover, the included Raspberry Pi will also be able to run a preconfigured Android system.
- You are welcome to bring your own BLE device. Having enough time we may be able to test its security.
What students will be provided with
- Course materials in PDFs (over 1000 pages)
- All required additional files: source code, documentation, installation binaries, virtual machine images
- Take-away hardware pack of about 200$ value for hands-on exercises, consisting of sample BLE device and attack tools:
- Raspberry Pi running 2 systems: Linux (stable environment with all the tools preinstalled) and Android (acting as a phone with live packet dump to Wireshark, root, various applications)
- Two Bluetooth sniffers (Nordic, SniffLE)
- BLE training device (simulating/attacking real hardware)
- Bluetooth Low Energy USB dongles
Share this post
Twitter
Google+
Facebook
Reddit
LinkedIn
StumbleUpon
Email