🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

~/ › Threat Intelligence › article

Threat Intelligence

Keyless Relay Attacks: How Syndicates Steal Cars Without Breaking Glass

> By ChenHo | Aug 04, 2026 | 4 min read

Your smart car keys are safely resting on your kitchen counter, yet a thief just drove your brand new SUV off the driveway without triggering a single alarm or breaking a window.

⚠️ THREAT INTELLIGENCE ADVISORY:
Organized syndicates are utilizing low-cost radio frequency (RF) amplifiers to execute “Relay Attacks.” By tricking the vehicle into detecting the key’s proximity, attackers can unlock and start modern cars seamlessly.

Relay Attacks

The transition to keyless entry systems has inadvertently replaced physical security with a highly exploitable digital convenience.

> TABLE_OF_CONTENTS [toggle]

Table of Contents

> THREAT_INTELLIGENCE_DATA

Context / Motivation

Luxury and mid-range SUVs are prime targets for international export syndicates. Traditional hotwiring is obsolete against modern immobilizers. Instead, attackers exploit the vehicle’s native “smart key” functionality, ensuring the car is stolen intact without any physical damage.

Technical Analysis: Signal Amplification

The attack requires two individuals working in tandem using a pair of radio transceivers.

> THREAT_INTELLIGENCE_DATA

  • The Relay Bridge: Attacker A stands near the car with a transmitter. The car constantly polls for the key’s low-frequency signal. Attacker A’s device captures this “challenge” signal and transmits it via a high-frequency link to Attacker B.
  • Key Interaction: Attacker B stands near the front door or window of the victim’s house. Their receiver amplifies the car’s challenge signal through the walls. The legitimate key on the kitchen counter responds.
  • Authentication: The key’s valid response is relayed back to Attacker A, who transmits it to the car. The car unlocks and starts, believing the owner is in the driver’s seat.

This hardware-level exploitation takes less than 60 seconds.

Impact Assessment

Victims suffer total asset loss, often waking up to an empty driveway. Insurance claims can be complicated if there is no evidence of forced entry, leaving owners in protracted battles with their providers.

Mitigation Recommendations

  1. Use a Faraday Pouch: Store your keys in an RF-blocking Faraday bag or a metal tin box when at home to prevent the signal from being amplified.
  2. Disable Keyless Entry: Check your vehicle’s manual; some manufacturers allow you to disable the keyless entry feature entirely via the infotainment system.
  3. Steering Wheel Locks: Reintroduce physical security barriers. A heavy-duty steering wheel lock severely deters attackers seeking a fast, silent getaway.

Mitigation & Prevention Strategies

Exploitation of vulnerabilities in critical infrastructure and edge devices requires immediate remediation to prevent catastrophic disruption:

  • Patch Management: Apply vendor-supplied security patches or firmware updates immediately. For legacy systems, deploy virtual patching via network firewalls.
  • Isolate OT Networks: SCADA and OT environments must be strictly isolated from corporate IT networks (the Purdue Model) to prevent spillover attacks.
  • Continuous Monitoring: Deploy Endpoint Detection and Response (EDR) solutions and monitor network traffic for indicators of compromise (IoCs) associated with known exploits.

Keyless Relay, Plainly

A relay attack stretches the radio handshake between your key fob in the kitchen and the car at the curb. Two people, two amplifiers, a few seconds. No broken glass. The car thinks the fob is in range. This is a physical radio attack, not an app hack. Faraday pouches and disabling walk-up unlock are the boring controls that work. After-market alarms that ignore the OEM radio do not always help.

Mitigation & Prevention Strategies

For owners.

  • Keep fobs away from the front door. Use the brand’s “walk-away lock / disable comfort access” setting. A metal tin or certified Faraday pouch at night is cheap insurance.
  • If the car supports a PIN to drive, turn it on.

For dealers / condos.

  • Camera coverage on the drop-off lane. Do not leave keyless press cars on the street overnight with fobs at reception.

Condo Lobbies

Fobs on a bowl at reception are a relay gift. Ask the condo to keep them in a drawer, not on the marble. If you valet, take the fob into the restaurant. Comfort-access is a convenience feature designed for your driveway, not for a street with two people and a backpack.

Write the control you will actually keep. A rule nobody follows is not a control. Put it on a card on the router, in the family chat, or in the staff handbook. Review it when you change phones, move house, or hire. Most of the failures in this class are forgotten defaults, not genius attackers. If you do only one thing tonight with the fob location, do the one already listed in the mitigation bullets above, then tell one other person in the household or team that you did it so the knowledge does not sit in a single head. If you cannot name the last time you checked, assume it is already wrong and check tonight.

Disclaimer: The information presented in this threat intelligence report is for educational and cybersecurity research purposes only. CyberAsia reports on cyber incidents to help organizations understand and defend against emerging threats. We do not provide hacking instructions, host stolen data, or endorse illegal activities.

> INTELLIGENCE_NOTICE

The report above detailing Keyless Relay Attacks: How Syndicates Steal Cars Without Breaking Glass is part of the CyberAsia public archive. For organizations requiring Indicators of Compromise (IoCs), YARA signatures, and specialized malware containment guidelines for threat intelligence threats, please refer to our Secure Drop or contact the research desk.

> ABOUT_AUTHOR: ChenHo

ChenHo is a Lead Threat Hunter and CTI Technical Contributor at CyberAsia, covering hacktivism networks, distributed denial-of-service (DDoS) telemetry, industrial SCADA systems, and emerging open-source intelligence (OSINT).

> related_intel --suggest