Attacks
Send BLE advertisement spam and spoof AirTags
On this page
Broadcast fake BLE advertisements to simulate nearby devices, or spoof Apple AirTags and other Find My devices. You need a Bluetooth-capable GhostESP; attacks are not available on ESP32-S2.
Wi-Fi impact: BLE spam and spoofing pause the GhostNet AP until you run
stop(or the task ends). See Scanning for how BLE sessions affect Wi-Fi.
Legal and Ethical
Most modern devices (iOS 17+, Android 14+, Windows) block these attacks. They mostly affect older devices.
Do not use BLE attacks in public. They can crash devices and disrupt essential services.
Only use these features on devices you own or have permission to test.
BLE Advertisement Spam
On-Device UI
- Open BLE → Spam. You should see the spam options.
- Choose a spam type from the options below (for example, BLE Spam - Apple). The device will start broadcasting advertisements. Leave it running as long as you want.
- Select Stop BLE Spam to stop broadcasting. The device will show a summary of packets sent.
CLI
- Open the GhostESP terminal.
- Run
blespam [TYPE]where the type is one of the modes below (for example,blespam -apple). The device will start broadcasting. - Run
blespam -sorstopwhen you’re done. The device will stop and show a summary.
Spam Modes
Apple Device Spam
- UI: BLE → Spam → BLE Spam - Apple
- CLI:
blespam -apple - Broadcasts fake Apple device advertisements (AirPods, Apple TV, HomePod, AirTags, etc.).
- Uses Apple’s Continuity Protocol with randomized device types and colors.
- Nearby Apple devices may show pairing prompts or connection notifications.
Microsoft Swift Pair Spam
- UI: BLE → Spam → BLE Spam - Microsoft
- CLI:
blespam -msorblespam -microsoft - Broadcasts fake Microsoft device advertisements with random device names.
- Targets Windows devices with Swift Pair notifications.
Samsung Device Spam
- UI: BLE → Spam → BLE Spam - Samsung
- CLI:
blespam -samsung - Broadcasts fake Samsung Galaxy Watch and other Samsung device advertisements.
- Targets Android devices with Samsung pairing prompts.
Google Fast Pair Spam
- UI: BLE → Spam → BLE Spam - Google
- CLI:
blespam -google - Broadcasts fake Google device advertisements using Google’s Fast Pair protocol.
- Targets Android devices with Google pairing notifications.
Random Spam
- UI: BLE → Spam → BLE Spam - Random
- CLI:
blespam -random - Cycles through all spam types (Apple, Microsoft, Samsung, Google) randomly.
- Broadcasts a mix of different device types to maximize disruption.
Custom Popup Name
- UI: BLE → Spam → BLE Spam - AirPods Popup Name
- CLI:
blespam -name <text> - Sets the advertised name used by the spam modes (for example a fake AirPods popup name).
- Names are capped at 20 characters, sanitized to printable ASCII, and truncated to the first 14 characters inside Apple ProximityPair frames; the full name is still sent in the scan response and Swift Pair advertisements.
AirTag Spoofing
Spoof Apple AirTags and other Find My devices to broadcast their location. This makes your device appear as a legitimate AirTag to nearby Apple devices.
Workflow
Scan for AirTags
- Run
blescan -a, or runbledetectto classify nearby trackers. - On-device, Start AirTag Scanner lives under the GhostLink BLE submenu, not the BLE menu.
- While the scanner is running, RSSI for already discovered AirTags is logged every few seconds in the terminal to show proximity changes.
- Wait for the scan to complete.
- Run
List discovered AirTags
- Run
listairtags, orbledetect -lto list detected devices with their index numbers. - You should see a list of discovered AirTags with their index numbers.
- Run
Select an AirTag to spoof
- Run
selectairtag <index>and enter the index number of the AirTag you want to spoof. - Alternatively,
bledetectcan spoof a detected AirTag directly.
- Run
Start spoofing
- Run
spoofairtag, or runbledetect -sp <index>to spoof a detected AirTag. - The device will broadcast as the selected AirTag.
- Nearby Apple devices will see your device as that AirTag.
- Run
Stop spoofing
- Run
stopspoof. - The device will stop broadcasting the AirTag advertisement.
- Run
Notes
- Spam and spoofing are independent: starting one does not stop the other, so stop each explicitly.
blespamaccepts its flags in any order (for exampleblespam -apple -name "My AirPods");-msis an alias for-microsoft.- Running
blespam -sstops the advertisements but leaves Wi-Fi suspended until you runstop. - The device broadcasts continuously until you explicitly stop it.
- Spam packet counts are logged every 5 seconds to the terminal.
- Apple spam uses different advertising intervals (~30-40ms) than other spam types for better compatibility.
- Spoofing captures the full AirTag advertisement payload during scanning for accurate reproduction.
Troubleshooting
- Attacks not working: Check that your device has Bluetooth enabled and sufficient free memory.
- No AirTags found: Move closer to Apple devices with Find My enabled or try scanning again.
- Spoofing doesn’t appear on Apple devices: Ensure you’ve selected a valid AirTag before starting spoofing. Try stopping and restarting the spoof.
