NEWS A Bluetooth speaker can infect a computer, even if no one touched it. A new way to attack without pairing and checking

Gold Surfer

Administrator
Staff member
Administrator
Moon-Club
Exclusive
Infinity
Premium
Member
Joined
Jan 20, 2026
Messages
345
Reaction score
2,220
A Creative column that decided to play the keyboard and hack your PC.
1780774844301.png
The column, connected to the computer via USB, suddenly turned into a bridge for remote burglary. Security specialist Rasmus Moorats found that the popular sound Blaster Katana V2X speaker system allows the attacker to download his own firmware on Bluetooth, and then execute commands on a connected PC without even touching the device.

The problem was solved by accident. After buying Sound Blaster Katana V2X, Moorats decided to study how the speaker is exchanging data with a computer. During the analysis, he discovered the proprietary Creative Transport Protocol (CTP), which allows you to control the backlight, equalizer and other functions of the device.

It turned out that the Bluetooth device can connect to the column without authentication and even without prior pairing. Moreover, one of the protocol commands allows you to download a new firmware. The manufacturer did not sign the firmware with a digital signature and did not add other verification mechanisms, so the column took the modified code without objection.

To begin with, the specialist downloaded a harmless version of the firmware, which simply displayed the word “patched” on the device display. Then attention was attracted by the operating system FreeRTOS, operating inside the column. FreeRTOS has a set of functions that allows the device to work as HID, which include keyboards, mice and other peripherals.
1780774869901.png
Text displayed on the column display (blog.nns.ee)

By default, HID was limited to playback and volume management. However, the specialist changed the USB descriptor of the device, adding keyboard functions. After that, the computer began to recognize the column as an additional input device, and the column was able to send key presses.

The next step was logical. Moorats forced the Bluetooth device to send commands to the column, and the column forced the functions of the keyboard to send commands to the computer. As a result, the specialist remotely updated the firmware through Bluetooth, rebooted the device and performed the “echo pwned” command on the connected computer.

The demonstration used a harmless team, but in a real attack, the attacker could open PowerShell and run malicious code. Moreover, the modified firmware is able to disable the mechanism of subsequent updates, which will make it difficult to attempt to remove the malware.

The situation is aggravated by the fact that Bluetooth remains active even in the sleepy mode of the column, and the standard way to completely disable the wireless interface is not provided.

In order for the column and connected computer to exchange data, authentication is provided. However, the defense was weak. The required response to the request can be extracted from the program supplied with the device. When the device is connected via Bluetooth, there is no such check at all.

The specialist reported the find of Creative Technology, but did not receive a response. After the intervention of the national response center CERT Singapore, the manufacturer still reacted. The company said it did not consider the described behavior to be a vulnerability.

The attack requires the attacker to be in the area of action of Bluetooth, so it is impossible to conduct it through the Internet. For successful hacking, the attacker needs to be nearby: in a nearby apartment, a neighboring office or the same room. However, the find shows that a regular Bluetooth speaker can be an unexpected tool for hacking a computer and raises the question of how many other wireless devices have similar hidden capabilities.
 

BLACK VEIL

Well-known member
Member
Joined
Jul 29, 2026
Messages
56
Reaction score
27
Location
ABD
Website
www.shopier.com
A Creative column that decided to play the keyboard and hack your PC.
View attachment 289
The column, connected to the computer via USB, suddenly turned into a bridge for remote burglary. Security specialist Rasmus Moorats found that the popular sound Blaster Katana V2X speaker system allows the attacker to download his own firmware on Bluetooth, and then execute commands on a connected PC without even touching the device.

The problem was solved by accident. After buying Sound Blaster Katana V2X, Moorats decided to study how the speaker is exchanging data with a computer. During the analysis, he discovered the proprietary Creative Transport Protocol (CTP), which allows you to control the backlight, equalizer and other functions of the device.

It turned out that the Bluetooth device can connect to the column without authentication and even without prior pairing. Moreover, one of the protocol commands allows you to download a new firmware. The manufacturer did not sign the firmware with a digital signature and did not add other verification mechanisms, so the column took the modified code without objection.

To begin with, the specialist downloaded a harmless version of the firmware, which simply displayed the word “patched” on the device display. Then attention was attracted by the operating system FreeRTOS, operating inside the column. FreeRTOS has a set of functions that allows the device to work as HID, which include keyboards, mice and other peripherals.
View attachment 290
Text displayed on the column display (blog.nns.ee)

By default, HID was limited to playback and volume management. However, the specialist changed the USB descriptor of the device, adding keyboard functions. After that, the computer began to recognize the column as an additional input device, and the column was able to send key presses.

The next step was logical. Moorats forced the Bluetooth device to send commands to the column, and the column forced the functions of the keyboard to send commands to the computer. As a result, the specialist remotely updated the firmware through Bluetooth, rebooted the device and performed the “echo pwned” command on the connected computer.

The demonstration used a harmless team, but in a real attack, the attacker could open PowerShell and run malicious code. Moreover, the modified firmware is able to disable the mechanism of subsequent updates, which will make it difficult to attempt to remove the malware.

The situation is aggravated by the fact that Bluetooth remains active even in the sleepy mode of the column, and the standard way to completely disable the wireless interface is not provided.

In order for the column and connected computer to exchange data, authentication is provided. However, the defense was weak. The required response to the request can be extracted from the program supplied with the device. When the device is connected via Bluetooth, there is no such check at all.

The specialist reported the find of Creative Technology, but did not receive a response. After the intervention of the national response center CERT Singapore, the manufacturer still reacted. The company said it did not consider the described behavior to be a vulnerability.

The attack requires the attacker to be in the area of action of Bluetooth, so it is impossible to conduct it through the Internet. For successful hacking, the attacker needs to be nearby: in a nearby apartment, a neighboring office or the same room. However, the find shows that a regular Bluetooth speaker can be an unexpected tool for hacking a computer and raises the question of how many other wireless devices have similar hidden capabilities.
⛧ BLACK VEIL // PRIVATE SERVICES ⛧

“Some requests are never made publicly.”

01 — THE FIXER
Coordination of private requests, connections, and sensitive agreements.
$1,000

02 — THE BROKER
Mediation of communication and negotiation between private parties.
$2,500

03 — THE HANDLER
Management of private files and task processes.
$5,000

04 — THE GHOST
Private agent whose identity and background are kept confidential.
$10,000

05 — THE CLEANER
Control of complex situations and crisis management.
$15,000

06 — THE SPYMASTER
Sensitive information, intelligence analysis, and private investigation services.
$25,000

07 — BLACK CONTRACT
Preparation of highly confidential private agreements.
$50,000

08 — OMEGA ACCESS
BLACK VEIL's highest level exclusive service package.
$100,000

---

⛧ PRIVATE CONTACT

SESSION
"050bbbee83794febed3c001a153cf99f2474b71f0952ba019fc62a1b206401a819"

TELEGRAM
"@Cipher5Network"

"PRIVATE CHANNEL" (https://reference-url-citation.invalid/0)

---

"NO PUBLIC LISTING"
"PRIVATE REQUESTS ONLY"
"ACCESS BY APPROVAL"
"BLACK VEIL // 2026"

STATUS: "ACTIVE"
ACCESS: "RESTRICTED"
CLIENTS: "UNKNOWN"

 

Porter’s

Well-known member
Member
Joined
Jul 27, 2026
Messages
60
Reaction score
16
HELLO 👋 GET IN TOUCH WITH ME IF YOU’RE INTERESTED IN FRESH VALID


• UK 🇬🇧 CREDIT CARDS 💳


• CANADA CREDIT CARDS 💳


• AUS CREDIT CARDS 💳


• USA 🇺🇸 CREDIT CARDS 💳


• NON VBV AUTO ADD CC


• CC TO BTC


ALSO SELLS :

BANK LOGS


DUMPS WITH PINS


FULLZ


BANK STATEMENTS


BANK OPEN UPS


EBT PINS


ALL CHECKED & VALIDATED

NO OTP REQUIRED

FREE FULL WALKTHROUGH FOR NEWBIES


• TEXT ME HERE TO BUY 📥🔽


TELEGRAM : @nobudgett1


CHANNEL : https://t.me/+CuDZ9auFpRc3Mjkx


______________________________________
 

MATRİXELİTES

Well-known member
Member
Joined
Aug 4, 2026
Messages
443
Reaction score
51
A Creative column that decided to play the keyboard and hack your PC.
View attachment 289
The column, connected to the computer via USB, suddenly turned into a bridge for remote burglary. Security specialist Rasmus Moorats found that the popular sound Blaster Katana V2X speaker system allows the attacker to download his own firmware on Bluetooth, and then execute commands on a connected PC without even touching the device.

The problem was solved by accident. After buying Sound Blaster Katana V2X, Moorats decided to study how the speaker is exchanging data with a computer. During the analysis, he discovered the proprietary Creative Transport Protocol (CTP), which allows you to control the backlight, equalizer and other functions of the device.

It turned out that the Bluetooth device can connect to the column without authentication and even without prior pairing. Moreover, one of the protocol commands allows you to download a new firmware. The manufacturer did not sign the firmware with a digital signature and did not add other verification mechanisms, so the column took the modified code without objection.

To begin with, the specialist downloaded a harmless version of the firmware, which simply displayed the word “patched” on the device display. Then attention was attracted by the operating system FreeRTOS, operating inside the column. FreeRTOS has a set of functions that allows the device to work as HID, which include keyboards, mice and other peripherals.
View attachment 290
Text displayed on the column display (blog.nns.ee)

By default, HID was limited to playback and volume management. However, the specialist changed the USB descriptor of the device, adding keyboard functions. After that, the computer began to recognize the column as an additional input device, and the column was able to send key presses.

The next step was logical. Moorats forced the Bluetooth device to send commands to the column, and the column forced the functions of the keyboard to send commands to the computer. As a result, the specialist remotely updated the firmware through Bluetooth, rebooted the device and performed the “echo pwned” command on the connected computer.

The demonstration used a harmless team, but in a real attack, the attacker could open PowerShell and run malicious code. Moreover, the modified firmware is able to disable the mechanism of subsequent updates, which will make it difficult to attempt to remove the malware.

The situation is aggravated by the fact that Bluetooth remains active even in the sleepy mode of the column, and the standard way to completely disable the wireless interface is not provided.

In order for the column and connected computer to exchange data, authentication is provided. However, the defense was weak. The required response to the request can be extracted from the program supplied with the device. When the device is connected via Bluetooth, there is no such check at all.

The specialist reported the find of Creative Technology, but did not receive a response. After the intervention of the national response center CERT Singapore, the manufacturer still reacted. The company said it did not consider the described behavior to be a vulnerability.

The attack requires the attacker to be in the area of action of Bluetooth, so it is impossible to conduct it through the Internet. For successful hacking, the attacker needs to be nearby: in a nearby apartment, a neighboring office or the same room. However, the find shows that a regular Bluetooth speaker can be an unexpected tool for hacking a computer and raises the question of how many other wireless devices have similar hidden capabilities.
 

DARKWEB16 layers

Well-known member
Member
Joined
Aug 5, 2026
Messages
161
Reaction score
0
A Creative column that decided to play the keyboard and hack your PC.
View attachment 289
The column, connected to the computer via USB, suddenly turned into a bridge for remote burglary. Security specialist Rasmus Moorats found that the popular sound Blaster Katana V2X speaker system allows the attacker to download his own firmware on Bluetooth, and then execute commands on a connected PC without even touching the device.

The problem was solved by accident. After buying Sound Blaster Katana V2X, Moorats decided to study how the speaker is exchanging data with a computer. During the analysis, he discovered the proprietary Creative Transport Protocol (CTP), which allows you to control the backlight, equalizer and other functions of the device.

It turned out that the Bluetooth device can connect to the column without authentication and even without prior pairing. Moreover, one of the protocol commands allows you to download a new firmware. The manufacturer did not sign the firmware with a digital signature and did not add other verification mechanisms, so the column took the modified code without objection.

To begin with, the specialist downloaded a harmless version of the firmware, which simply displayed the word “patched” on the device display. Then attention was attracted by the operating system FreeRTOS, operating inside the column. FreeRTOS has a set of functions that allows the device to work as HID, which include keyboards, mice and other peripherals.
View attachment 290
Text displayed on the column display (blog.nns.ee)

By default, HID was limited to playback and volume management. However, the specialist changed the USB descriptor of the device, adding keyboard functions. After that, the computer began to recognize the column as an additional input device, and the column was able to send key presses.

The next step was logical. Moorats forced the Bluetooth device to send commands to the column, and the column forced the functions of the keyboard to send commands to the computer. As a result, the specialist remotely updated the firmware through Bluetooth, rebooted the device and performed the “echo pwned” command on the connected computer.

The demonstration used a harmless team, but in a real attack, the attacker could open PowerShell and run malicious code. Moreover, the modified firmware is able to disable the mechanism of subsequent updates, which will make it difficult to attempt to remove the malware.

The situation is aggravated by the fact that Bluetooth remains active even in the sleepy mode of the column, and the standard way to completely disable the wireless interface is not provided.

In order for the column and connected computer to exchange data, authentication is provided. However, the defense was weak. The required response to the request can be extracted from the program supplied with the device. When the device is connected via Bluetooth, there is no such check at all.

The specialist reported the find of Creative Technology, but did not receive a response. After the intervention of the national response center CERT Singapore, the manufacturer still reacted. The company said it did not consider the described behavior to be a vulnerability.

The attack requires the attacker to be in the area of action of Bluetooth, so it is impossible to conduct it through the Internet. For successful hacking, the attacker needs to be nearby: in a nearby apartment, a neighboring office or the same room. However, the find shows that a regular Bluetooth speaker can be an unexpected tool for hacking a computer and raises the question of how many other wireless devices have similar hidden capabilities.
Telegram Join our Telegram channel! Welcome to our Telegram channel, blacks Join our Telegram channel, blacks room! Welcome to our Telegram channel, Blacks Room continues to grow! Welcome to our Telegram channel, Blacks Room continues to grow! 186 Welcome to our Telegram channel, Blacks Room! We continue to grow and have 186 members. Welcome to our Telegram channel, Blacks Room! We continue to grow, we have 186 members and entries are welcome. Welcome to our Telegram channel, Blacks Room! We're growing, we have 186 members, and entry is free. Welcome to our Telegram channel, Blacks Room! We continue to grow, we have 186 members and entry is free. Welcome to our Telegram channel, Blacks Room! We continue to grow, we have 186 members, and entry is free, but you need to send messages. Welcome to our Telegram channel, Blacks Room! We continue to grow, we have 186 members, and entry is free, but we have strict moderators for messaging. Welcome to our Telegram channel, Blacks Room! We continue to grow, we have 186 members, and entry is free, but we've implemented strict measures for sending messages. Welcome to our Telegram channel, Blacks Room! We continue to grow, we have 186 members, and entry is free, but we've implemented strict measures for sending messages. 35 35,000 35,000 Telegrams Pay 35,000 Telegram stars and then send a message. You can pay 35,000 Telegram stars and then send a message. You can pay 35,000 Telegram stars and then send a message. You can pay 35,000 Telegram stars and then send messages. This Telegram feature is only for legitimate sellers. You can pay 35,000 Telegram stars and then send messages. This Telegram is only for legitimate sellers. You can pay 35,000 Telegram stars and then send a message. This Telegram account is only for legitimate sellers and secure shopping. You can pay 35,000 Telegram stars and then send a message. This Telegram app is only for legitimate sellers and secure shopping. You can pay 35,000 Telegram stars and then send a message. This Telegram account is only for legitimate sellers and secure transactions. You can pay 35,000 Telegram stars and then send a message. This Telegram account is only for legitimate sellers and secure transactions. Now Now he's a scammer. No more scams We are putting an end to these scams now. We are putting an end to scams now, Blacks Room is safe. We are putting an end to scams; shop safely at Blacks Room. We are putting an end to scams; Blacks Room allows you to shop safely. We are putting an end to scams; Blacks Room allows you to shop safely.

 
5,462Threads
74,636Messages
5,790Members
Darkshadow02Latest member
Top Bottom