Abstract
- This paper investigates a novel data exfiltration technique that abuses the Apple Find My network. The attack encodes sensitive information, such as credentials or credit card numbers, into BLE advertisements, which are then opportunistically relayed by nearby Apple devices to iCloud infrastructure. Unlike conventional methods, this approach bypasses IP-based communication and internet access, making it highly stealthy and difficult to trace. The prototype demonstrates end-to-end exfiltration from a compromised system using the SendMy framework, showcasing how attackers can abuse trusted hardware and infrastructure for wireless data leakage. We discuss the scalability, stealth and limitations of the attack and propose directions for future detection and mitigation strategies.