1/
WHEREAMI: Built a Chrome-based geolocation red team tool (bash script😅).
whoami tells you who. whereami tells you where.
Living-Off-the-Land (#LOLbins), no new binaries, no permissions prompts.
Relevant for proximity based attacks, e.g. @Volexity's nearest neighbor
Interesting realization: any bash script can get your geolocation.
Here done using Wi-Fi trilateration on macOS by spawning a chrome browser.
I would assume the same thing is possible on Linux, probably even without spawning a browser.
@TalBeerySec@Volexity Big thanks to @vanhoefm who also reminded the world that "Any Wi-Fi attack can now be a remote attack" That’s the gap @AirEye closes, continuous monitoring of the wireless layer, so you know when something, or someone - is where it shouldn’t be.
@TalBeerySec@Volexity Tools like this make it trivially easy for an attacker to confirm they’ve reached the right target network. What organizations are missing is the ability to detect rogue or wireless clients that violates company's policy, before they pivot inward.
This guide explores:
✅ Emerging antenna-for-hire threats
✅ Remote rogue AP deployments
✅ OT, IoT, and physical airspace risks you won’t see in traditional network maps
Thanks to @vanhoefm for inspiring the @AirEyeSecurity team to work on that threat modelling.
🚨 The AirEye research team has just published our 2025 Wireless Airspace Threat Modeling guide.
In an era where any Wi-Fi attack can now be a remote attack, understanding and securing your wireless airspace has never been more critical.
https://t.co/T9O2tDAr0D
.@Volexity’s latest blog post describes in detail how a Russian APT used a new attack technique, the “Nearest Neighbor Attack”, to leverage Wi-Fi networks in close proximity to the intended target, while the attacker was halfway around the world.
https://t.co/R3aKyrjVYR
#dfir
1/Hack thy neighbor!🧵
There is a bigger lesson here: We often dismiss (e.g. lower CVSS) attack vectors that require proximity.
However, in many cases the required attack stimulus can be generated via a hacked nearby system, making it remote!
CC:@thegrugq@RGB_Lights@ImposeCost
Wow, an adversary first compromised a neighbor of the target, and then attacked the target over Wi-Fi (with stolen password).
This is the first observed case of the #AntennaForHire attack that @AirEyeSecurity hypothesized.
Remember: any Wi-Fi attack can now be a remote attack
@DrLoupis__@DrLoupis Hamas held the Bibas family hostage for over 8 months, refused to provide proof of life, and cynically used them for propaganda. Israel never targeted its own hostages—Hamas is responsible for their deaths. #BringThemHomeNow
@DrLoupis__@DrLoupis Hamas’s failure to return Shiri’s body further underscores their disregard for human life and international agreements. Israel is committed to rescuing its citizens; the responsibility for these tragic deaths lies solely with Hamas.
@YosephHaddad Absolutely, it's tragic how HamasISIS uses their own people as human shields, showing no regard for Palestinian lives. They exploit hospitals, schools, and UN facilities to launch attacks, putting innocent civilians at risk. Israel's mission is to eradicate this terror.