Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Malware

usbliter8

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

11 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1200Hardware AdditionsEvidence2

Physical access, a USB connection, and manual placement of the device into DFU mode are required to perform the attack... There remains a strict physical access requirement for the attack: a target device must be manually placed into Device Firmware Update (DFU) mode and connected to an RP2350-based microcontroller platform using USB.

Execution

2 techniques
T1059Command and Scripting InterpreterEvidence1

Apple’s signature checks are bypassed, allowing a hacker to achieve full code execution at the device’s lowest level before the OS ever loads.

T1203Exploitation for Client ExecutionEvidence4

Conducting a Usbliter8 attack involves the attacker connecting a special USB device (eg, Raspberry Pi Pico 2 or similar microcontroller board) to the targeted iPhone and sending it crafted USB setup packets.

Persistence

4 techniques
T1542Pre-OS BootEvidence1

The attacker can load unsigned firmware or lower the device’s security level.

T1542.003BootkitEvidence2

Individuals who operate under elevated threat conditions... face a significantly different risk profile. In such scenarios, a compromised device based on A12, A13, S4, or S5 could be affected by persistent boot-level intrusions that are anchored underneath the operating system itself, even after software updates are applied.

T1547Boot or Logon Autostart ExecutionEvidence1

Once in control, the exploit installs a custom handler that survives a device restart and adds two capabilities: temporarily lowering the device's security settings, and booting unsigned software without any verification checks.

T1556Modify Authentication ProcessEvidence4

From that position an attacker can temporarily demote the SoC’s production mode or boot a raw, unsigned iBoot image with no signature checks, stepping entirely outside Apple’s chain of trust.

Privilege Escalation

2 techniques
T1068Exploitation for Privilege EscalationEvidence6

The attack triggers an out-of-bounds write, allowing the attacker to overwrite critical data in memory and ultimately take control of the processor, escalate privileges, and execute arbitrary code with full system privileges.

T1547Boot or Logon Autostart ExecutionEvidence1

Once in control, the exploit installs a custom handler that survives a device restart and adds two capabilities: temporarily lowering the device's security settings, and booting unsigned software without any verification checks.

Stealth

3 techniques
T1211Exploitation for Defense EvasionEvidence1

Paradigm Shift bypassed it in stages... Pointer Authentication (PAC) protects stack-stored return addresses... The final step overwrote the USB interrupt handler pointer in BSS. The next USB interrupt then ran attacker-supplied code.

T1542Pre-OS BootEvidence1

The attacker can load unsigned firmware or lower the device’s security level.

T1542.003BootkitEvidence2

Individuals who operate under elevated threat conditions... face a significantly different risk profile. In such scenarios, a compromised device based on A12, A13, S4, or S5 could be affected by persistent boot-level intrusions that are anchored underneath the operating system itself, even after software updates are applied.

Defense Impairment

2 techniques
T1553Subvert Trust ControlsEvidence1

Apple’s signature checks are bypassed, allowing a hacker to achieve full code execution at the device’s lowest level before the OS ever loads. The attacker can load unsigned firmware or lower the device’s security level.

T1556Modify Authentication ProcessEvidence4

From that position an attacker can temporarily demote the SoC’s production mode or boot a raw, unsigned iBoot image with no signature checks, stepping entirely outside Apple’s chain of trust.

Credential Access

1 technique
T1556Modify Authentication ProcessEvidence4

From that position an attacker can temporarily demote the SoC’s production mode or boot a raw, unsigned iBoot image with no signature checks, stepping entirely outside Apple’s chain of trust.

Other

1 technique
T1562Impair DefensesEvidence1

Once in control, the exploit installs a custom handler that survives a device restart and adds two capabilities: temporarily lowering the device's security settings, and booting unsigned software without any verification checks.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping11

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.