Skip to content
Bulwark Black Bulwark Black LLC
Threat Intel
  • Latest reporting
  • Russian CTI
  • Chinese CTI
  • North Korean CTI
  • Iranian CTI
  • Global / Anomalous
  • Malware
  • IOC / YARA downloads
Software
  • Contractor Codex ↗
  • SAMscout AI ↗
  • VA Disability Calc & Track
  • What we build
  • All software
Services
  • Websites & Web Apps
  • Custom iOS Apps
  • AI & Automation
  • Small-Business IT & Cybersecurity
Company
  • About
  • Community
  • Contact
IOC Extractor Indicators Feeds The Brief Blog
Threat Intel → Work with us →
All Threat Intel → Latest reporting Russian CTI Chinese CTI North Korean CTI Iranian CTI Global / Anomalous Malware IOC / YARA downloads
All Software → Contractor Codex ↗ SAMscout AI ↗ VA Disability Calc & Track What we build All software
All Services → Websites & Web Apps Custom iOS Apps AI & Automation Small-Business IT & Cybersecurity
All Company → About Community Contact
IOC Extractor Indicators Feeds The Brief Blog Work with us →
RSS
Latest
BTR.sys Shows Why Trusted Security Drivers Need Behavioral MonitoringWeedHack Shows SEO Poisoning Is Malware Delivery InfrastructureAI Agent Incidents Need Task-Scoped Incident ResponseSDLC Supply-Chain Attacks Show Why Developer Tools Need Runtime ControlsRussian Auth-Flow Phishing Shows MFA Can Be Bypassed Without ExploitsFake AI Tools Show Brand Trust Has Become Malware DeliveryStopAndProtect Shows Why WordPress Sites Are Attack InfrastructureMacSync Stealer Shows Why Behavioral Pivots Beat Rotating DomainsPurpleDelta Shows Why Remote Hiring Is Now an Insider-Risk ControlGitLab GraphQL Flaw Shows Why DevSecOps Platforms Need Emergency Patch RunbooksForminator RCE Shows Why WordPress Plugin Risk Needs Runtime ControlsC2Looper Shows Why GitHub-Based C2 Belongs in Ransomware TriageVMware vCenter Exploitation Shows Why Patching Is Not Incident ClosureRansomware’s Long Tail Means Defenders Need Faster TriageBTR.sys Shows Why Trusted Security Drivers Need Behavioral MonitoringWeedHack Shows SEO Poisoning Is Malware Delivery InfrastructureAI Agent Incidents Need Task-Scoped Incident ResponseSDLC Supply-Chain Attacks Show Why Developer Tools Need Runtime ControlsRussian Auth-Flow Phishing Shows MFA Can Be Bypassed Without ExploitsFake AI Tools Show Brand Trust Has Become Malware DeliveryStopAndProtect Shows Why WordPress Sites Are Attack InfrastructureMacSync Stealer Shows Why Behavioral Pivots Beat Rotating DomainsPurpleDelta Shows Why Remote Hiring Is Now an Insider-Risk ControlGitLab GraphQL Flaw Shows Why DevSecOps Platforms Need Emergency Patch RunbooksForminator RCE Shows Why WordPress Plugin Risk Needs Runtime ControlsC2Looper Shows Why GitHub-Based C2 Belongs in Ransomware TriageVMware vCenter Exploitation Shows Why Patching Is Not Incident ClosureRansomware’s Long Tail Means Defenders Need Faster Triage

Threat Intel·Offensive Devices / Tactics·Jan 11, 2024·By Albert LaScola

FAKING BLUETOOTH LE WITH AN NRF24L01+ MODULE

FAKING BLUETOOTH LE WITH AN NRF24L01+ MODULE
Faking Bluetooth LE With An nRF24L01+ Module

#Bluetooth#NRF24L01+ MODULE

Indicators of Compromise

4 indicators, auto-extracted and defanged.

TXTCSVJSONYARA

Domains (2)

hackaday[.]iowww[.]sparkfun[.]com

URLs (2)

hxxps://hackaday[.]io/project/162131-graphical-pinout-generator/hxxps://www[.]sparkfun[.]com/news/1947

Auto-extracted from this report. Indicators shown are defanged for safe viewing. The downloads contain live values plus a YARA rule for tooling. Verify before acting.

← Older report

SCADA systems: How secure are the systems running our infrastructure?⎥Malav Vyas (Security Researcher at Palo Alto Networks)

Newer report →

Automating C2 Infrastructure with Terraform, Nebula, Caddy and Cobalt Strike

Next step

Want this turned into detection for your environment?

We build the defenses we write about: detection rules, hardening, and incident response for small businesses and government contractors. Or take the indicators above and run them yourself, every report ships with machine-readable downloads.

Work With Us →Get the IOC Feeds →

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

readers get The Brief

Double opt-in. One-click unsubscribe on every issue. We never share your address.

Bulwark Black

Veteran-Owned · SDVOSB

Bulwark Black LLC
Cyber threat intelligence, custom software, and remote tech help.
Remote across the United States.

Registered agent address (mailing only):
522 W Riverside Ave, Ste N
Spokane, WA 99201

Two front doors

  • Cyber Threat Intelligence
  • Indicator Database
  • Threat Feeds
  • Shared Infrastructure
  • Threat Alerts
  • The Brief
  • Tech Services & Apps

Services

  • Websites & Web Apps
  • Custom iOS Apps
  • AI & Automation
  • IT + Cybersecurity

Company

  • About
  • Software
  • VA Disability Calc & Track
  • Community
  • Blog
  • How I Work
  • Contact
  • Privacy
  • Terms
  • VA Calc Privacy Policy

For agencies & primes

  • Capability statement
  • CAGE: 17UL6
  • UEI: DVNTWBJ2HMP8
  • SDVOSB · SAM Registered

support@bulwarkblack.com

Connect

  • LinkedIn
  • GitHub

© 2026 Bulwark Black LLC. All rights reserved.

Privacy · Terms · Cookie choices

We use Google Analytics to measure site traffic, which sets cookies. No ads and no cross-site tracking. See our privacy policy.