Title: Attacks Description: Send BLE advertisement spam and spoof AirTags. URL: /v2.1/ble/attacks/ Version: v2.1 Section: Bluetooth LE Search index: /search-index.json # Attacks > Send BLE advertisement spam and spoof AirTags. ## On this page - [Prerequisites](#prerequisites) - [Legal and ethical](#legal-and-ethical) - [Patches and Mitigations](#patches-and-mitigations) - [Safety Warnings](#safety-warnings) - [BLE Advertisement Spam](#ble-advertisement-spam) - [On-device UI](#on-device-ui) - [Command line](#command-line) - [Spam modes](#spam-modes) - [Apple Device Spam](#apple-device-spam) - [Microsoft Swift Pair Spam](#microsoft-swift-pair-spam) - [Samsung Device Spam](#samsung-device-spam) - [Google Fast Pair Spam](#google-fast-pair-spam) - [Random Spam](#random-spam) - [AirTag Spoofing](#airtag-spoofing) - [Workflow](#workflow) - [Notes](#notes) - [Troubleshooting](#troubleshooting) --- Broadcast fake BLE advertisements to simulate nearby devices or spoof Apple AirTags and other Find My devices. Wi-Fi impact: Starting a BLE spam or spoofing session pauses the GhostNet AP until you run stop (or the task ends). Wi-Fi resumes automatically when BLE deinitializes. ## Prerequisites - GhostESP flashed device, powered on with a wireless antenna. - Device must support Bluetooth (not available on ESP32-S2). ## Legal and ethical ### Patches and Mitigations Most modern devices (iOS 17+, Android 14+, Windows) block these attacks. They mostly affect older devices. ### Safety Warnings Do not use BLE attacks in public. They can crash devices and disrupt essential services. Only use these features on devices you own or have permission to test. ## BLE Advertisement Spam Broadcast fake BLE advertisements to simulate nearby devices. ### On-device UI - Open Menu → Bluetooth → Spam. You should see the spam options. - Choose a spam type from the options below (for example, BLE Spam - Apple). The device will start broadcasting advertisements. Leave it running as long as you want. - Select Stop BLE Spam to stop broadcasting. The device will show a summary of packets sent. ### Command line - Open the GhostESP terminal. - Run blespam [TYPE] where the type is one of the modes below (for example, blespam -apple). The device will start broadcasting. - Run blespam -s or stop when you’re done. The device will stop and show a summary. ### Spam modes #### Apple Device Spam - UI: Menu → Bluetooth → Spam → BLE Spam - Apple - CLI: blespam -apple - Broadcasts fake Apple device advertisements (AirPods, Apple TV, HomePod, AirTags, etc.). - Uses Apple’s Continuity Protocol with randomized device types and colors. - Nearby Apple devices may show pairing prompts or connection notifications. #### Microsoft Swift Pair Spam - UI: Menu → Bluetooth → Spam → BLE Spam - Microsoft - CLI: blespam -ms or blespam -microsoft - Broadcasts fake Microsoft device advertisements with random device names. - Targets Windows devices with Swift Pair notifications. #### Samsung Device Spam - UI: Menu → Bluetooth → Spam → BLE Spam - Samsung - CLI: blespam -samsung - Broadcasts fake Samsung Galaxy Watch and other Samsung device advertisements. - Targets Android devices with Samsung pairing prompts. #### Google Fast Pair Spam - UI: Menu → Bluetooth → Spam → BLE Spam - Google - CLI: blespam -google - Broadcasts fake Google device advertisements using Google’s Fast Pair protocol. - Targets Android devices with Google pairing notifications. #### Random Spam - UI: Menu → Bluetooth → Spam → BLE Spam - Random - CLI: blespam -random - Cycles through all spam types (Apple, Microsoft, Samsung, Google) randomly. - Broadcasts a mix of different device types to maximize disruption. ## AirTag Spoofing Spoof Apple AirTags and other Find My devices to broadcast their location. This makes your device appear as a legitimate AirTag to nearby Apple devices. ### Workflow - Scan for AirTags Open Menu → Bluetooth → AirTag → Start AirTag Scanner or run blescan -a. - While the scanner is running, RSSI for already discovered AirTags is logged every few seconds in the terminal to show proximity changes. - Wait for the scan to complete. - List discovered AirTags Open Menu → Bluetooth → AirTag → List AirTags or run list -airtags. - You should see a list of discovered AirTags with their index numbers. - Select an AirTag to spoof Open Menu → Bluetooth → AirTag → Select AirTag. - Enter the index number of the AirTag you want to spoof. - Start spoofing Open Menu → Bluetooth → AirTag → Spoof Selected AirTag or run spoofairtag. - The device will broadcast as the selected AirTag. - Nearby Apple devices will see your device as that AirTag. - Stop spoofing Open Menu → Bluetooth → AirTag → Stop Spoofing or run stopspoof. - The device will stop broadcasting the AirTag advertisement. ## Notes - BLE attacks are not available on ESP32-S2 devices. - Spam attacks and spoofing are mutually exclusive; starting one will stop the other. - The device broadcasts continuously until you explicitly stop it. - Spam packet counts are logged every 5 seconds to the terminal. - Apple spam uses different advertising intervals (~30-40ms) than other spam types for better compatibility. - Spoofing captures the full AirTag advertisement payload during scanning for accurate reproduction. ## Troubleshooting - Attacks not working: Check that your device has Bluetooth enabled and sufficient free memory. The AP pauses during attacks—if you need the web UI during testing, stop BLE first or use GhostLink. - No AirTags found: Move closer to Apple devices with Find My enabled or try scanning again. - Spoofing doesn’t appear on Apple devices: Ensure you’ve selected a valid AirTag before starting spoofing. Try stopping and restarting the spoof. - Bluetooth not supported: Ensure you’re using a device other than ESP32-S2, which does not have Bluetooth support.