Bluebugging

A Bluetooth attack that exploits firmware flaws in some older devices to use the device's own commands, such as placing calls, sending messages or reading data, without the owner knowing.

Bluebugging is an attack in which someone within radio range takes control of a Bluetooth device’s functions without the owner’s knowledge. NIST SP 800-121 Rev 2, Guide to Bluetooth Security, lists it among the Bluetooth-specific attacks and describes it as exploiting a firmware flaw in some older devices, from around 2004, to reach the device and its commands. On a vulnerable phone that meant the attacker could read data, place calls, listen in on calls and send messages.

Study sources commonly teach bluebugging with two other Bluetooth attacks, and the three are told apart by what the attacker gains. Bluejacking only sends unsolicited messages. Bluesnarfing copies data off the device. Bluebugging goes further than either, because it uses the device itself. Because it depends on specific firmware flaws, it is taught for recognition rather than as a picture of how current devices are attacked. The lasting controls still apply: keep firmware updated, keep devices non-discoverable when they do not need to be found, and pair only with known devices.

Exam relevance: a scenario is likely to describe a phone that places calls or sends messages its owner never made, with a Bluetooth link as the only path. Candidates are expected to match control of the device to bluebugging, data theft to bluesnarfing and unsolicited messages to bluejacking.