🔧 ProgrammierungThe Cascade Runs Ahead of the Flip(16.09.2026 um 02:21 Uhr)
🔧 ProgrammierungWeekly Dev Log 2026-W19(16.09.2026 um 02:30 Uhr)
🔧 ProgrammierungI wanted to remember what changed after an AI coding session(16.09.2026 um 02:34 Uhr)
🔧 ProgrammierungYour change process governs code. This was not code.(16.09.2026 um 02:39 Uhr)
🔧 ProgrammierungRadio: A Shared Channel for my AI Agents(16.09.2026 um 02:40 Uhr)
🔧 ProgrammierungThe Cascade Runs Ahead of the Flip(16.09.2026 um 02:21 Uhr)
🔧 ProgrammierungWeekly Dev Log 2026-W19(16.09.2026 um 02:30 Uhr)
🔧 ProgrammierungI wanted to remember what changed after an AI coding session(16.09.2026 um 02:34 Uhr)
🔧 ProgrammierungYour change process governs code. This was not code.(16.09.2026 um 02:39 Uhr)
🔧 ProgrammierungRadio: A Shared Channel for my AI Agents(16.09.2026 um 02:40 Uhr)

🎥 IT Security Video 🕛 vor 5 Monaten 2 Min Lesezeit SECURITY-FEED
0

Black Hat USA 2025 | Ransomware, Tracking, DoS, and Data Leaks on Xiaomi Electric Scooters

↗ Quelle (YouTube)
🗣️ Stimme:
📺
YouTube

Author: Black Hat - Bewertung: 0x - Views:41

We present a broad security and privacy assessment of the internals of two popular Xiaomi e-scooters: the M365 (2016) and Mi3 (2023). The internals include a battery management system (BMS), an electric motor controller (DRV), and a Bluetooth Low Energy subsystem (BTS). We also analyze Mi Home, the official Xiaomi e-scooter companion app for Android and iOS.



We uncovered four critical vulnerabilities through extensive static and dynamic reverse engineering, including a remote code execution flaw in the BMS. We exploit the vulnerabilities to conduct four novel attacks we call E-Trojans. The attacks can be executed remotely via a malicious mobile application installed on the victim's phone or in wireless proximity using a Bluetooth Low Energy (BLE) device. The attacks affect the e-scooter safety, security, availability, and privacy. For example, we present a new ransomware attack infecting the BMS and asking for a ransom while permanently damaging the e-scooter battery by silently undervolting its cells.



We present the E-Trojans toolkit, an open-source and modular toolkit for reproducing our attacks and experimenting with Xiaomi e-scooters. The toolkit contains an automated patching module that creates modified BMS firmware with malicious capabilities, such as disabling firmware updates and overriding the battery safety thresholds. The toolkit also includes the Android app and Django/MongoDB backend required by our ransomware.



Empirical tests confirm our attacks' effectiveness and practicality. For instance, our undervoltage ransomware can permanently reduce the autonomy of an M365 battery by 50% in three hours while asking for a ransom. We propose four countermeasures to enhance the security and privacy of the Xiaomi e-scooter ecosystem.



By:

Marco Casagrande | Security Researcher, KTH

Daniele Antonioli | Professor, EURECOM



Presentation Materials Available at:

https://blackhat.com/us-25/briefings/schedule/?#e-trojans-ransomware-tracking-dos-and-data-leaks-on-xiaomi-electric-scooters-45822

Vollständiges Original-Advisory
Ausführliche Details, Exploit-Analyse & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Building a SOC 2 Evidence Collector: A Small-Team Alternative to Manual Audit Prep
1 Quelle
From Ring to Repo: Predicting Developer Fatigue Using Oura Data and Random Forest
1 Quelle
The Cascade Runs Ahead of the Flip
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Black Hat USA 2025 | Ransomware, Tracking, DoS, and Data Leaks on Xiaomi Electric Scooters

Thematisch verwandte Begriffe: Black, 2025, Ransomware, Tracking · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...