Most Powerful BadUSB Payload on Flipper Zero! Keylogger w/ Credential Stealer & File Downloader!

Sdílet
Vložit
  • čas přidán 11. 08. 2023
  • This week I was working with InfoSecREDD on what is definitely the most powerful BadUSB I've ever seen on the Flipper Zero!! This features a working keylogger with clipboard and credential stealer and a bonus payload showing off a file exfiltrator that's controlled by a Command and Control server and even has a global killswitch!! Even better, everything gets sent directly to your Discord server!
    REDD's Github : github.com/InfoSecREDD
    PowerShell Command to Enable Script Use:
    Set-ExecutionPolicy -ExecutionPolicy Unrestricted -Scope CurrentUser
    -----------------------------------
    Check Out The Official Squachtopia Hangout Discord Server!:
    / discord
    -----------------------------------
    Support the Channel at my Patreon!!
    www.patreon.com/user?u=29290751
    -----------------------------------
    Follow me on Social Media!
    TikTok : / talkingsasquach
    Instagram : / talking_sasquach
    -----------------------------------
    Thank You SO MUCH For I am Jakoby for the intro, definitely hit up his channel and be sure to subscribe!!!
    / iamjakoby
    -----------------------------------
  • Věda a technologie

Komentáře • 86

  • @rafita8871
    @rafita8871 Před 9 měsíci +31

    Thats why redd is the best

    • @TalkingSasquach
      @TalkingSasquach  Před 9 měsíci +7

      For real, he's a badass!

    • @rafita8871
      @rafita8871 Před 9 měsíci +4

      @@TalkingSasquach not only in tech he also gives good life tips ;)

    • @TalkingSasquach
      @TalkingSasquach  Před 9 měsíci +2

      @@CatVSDog. go for it!! REDD will be releasing the code for the file exfiltrator soon so you can check that out when he does

    • @alperayik
      @alperayik Před 7 měsíci

      @@TalkingSasquach awesome video as usual... Did he release it yet?

    • @kylewalker6746
      @kylewalker6746 Před 7 dny

      Who is Redd?

  • @_mk5Gti_
    @_mk5Gti_ Před 9 měsíci +7

    Love ur content, thanks 4 bringing me in the flipper zone (im from germany and i have absolut no clue about coding and stuff. But thanks to you im getting in to it) ❤

  • @Jaxx7594
    @Jaxx7594 Před 9 měsíci +5

    very cool! Redd is clearly talented. I reckon one thing that would make it better is utilising discord embeds though, because then you could have a menu with a bunch of controls. I might try to remake this, it looks like a fun project

    • @InfoSecREDD
      @InfoSecREDD Před 9 měsíci

      Yeah, this is just using Webhooks so no data from discord is being sent to the victim machine. Just from victim machine to Discord. Making a full on bot to do so would of taken more time.

  • @bmx135536
    @bmx135536 Před 9 měsíci +6

    Chat GPT wrote one back when it was on 2.0 model.. Finally, the good stuff we have been waiting for...

  • @juliobrs
    @juliobrs Před 9 měsíci +24

    Great video! Just a small correction: That's not encryption, that's simple encoding. Encryption requires a key to decipher while base64 encoding can be reversed easily. The use of the base64 certificate encoding function idea was clever to hide it from the system, though. Cheers ✌🏼

    • @TalkingSasquach
      @TalkingSasquach  Před 9 měsíci +8

      Yup! I was waiting for this comment. We are aware it's not encrypting, but I'm smooth brain and I kept saying it anyway

    • @InfoSecREDD
      @InfoSecREDD Před 9 měsíci +8

      Yep, I'm aware.. Just "Redds Payload Enocoder Generator" sounded too weird. Plus with future versions Encryption will be a possibility.

    • @TalkingSasquach
      @TalkingSasquach  Před 9 měsíci +3

      @@InfoSecREDD it's the man himself!! Great work!

    • @xss.getganked
      @xss.getganked Před 6 měsíci

      ​@@InfoSecREDDhey man do you have a way I can contact you ??

  • @bmx135536
    @bmx135536 Před 9 měsíci +9

    Redd is definitely not just a hobbyist, such as myself.
    He is a monster breed in a government facility that trains children from a young age.. 😂

  • @farinhoca
    @farinhoca Před 3 měsíci +3

    My Windows 10 did not let me execute the command in PowerShell, after executing the payload on the target machine

  • @audiokidnapping6464
    @audiokidnapping6464 Před 9 měsíci +1

    yah man thx for all your stuff

  • @reviewithme9913
    @reviewithme9913 Před 21 dnem

    He’s like the “donut” of the tech world

  • @Zardoz66
    @Zardoz66 Před 9 měsíci +1

    this is indeed crazy stuff. redd is the best.

  • @theunheardprophet4315
    @theunheardprophet4315 Před 3 měsíci

    +1 for the Mosko Moto shirt

  • @JulianQuinn
    @JulianQuinn Před 6 měsíci +1

    man I really wish I had that code to play around with! so cool

  • @InfBlade
    @InfBlade Před 9 měsíci +3

    This is very cool

  • @redw0lf848
    @redw0lf848 Před 2 měsíci +4

    so why are we here if we cant have the code? lol closed

  • @Unknown03_
    @Unknown03_ Před 5 měsíci

    Is it possible to make a usb with can save everything a windows computer type and it doesn’t appear into the computer?
    And is it possible to run the bad usb without connecting it to the computer??🤔

  • @jamescook5931
    @jamescook5931 Před 3 měsíci +1

    Could you share with me the laptop you’re using in this video?

  • @MrLogic364
    @MrLogic364 Před 9 měsíci

    Frikkn awesome

  • @pathommaneerattanapruek2345
    @pathommaneerattanapruek2345 Před 9 měsíci +2

    where can i get payloads?

  • @Luca-gb1og
    @Luca-gb1og Před 9 měsíci

    Hey, I wonder if you can emulate saved nfc „tags“ with the flipper zero app. On the their website there was a button on the app to emulate a saved nfc but idk if it’s being emulated on the flipper or with the phones nfc chip. And if it’s being emulated with the phones nfc chip, does the flipper has to be connected for it to work?

    • @RightMath
      @RightMath Před 8 dny

      can, every credit card has a special product key that cannot be bypass, we’ve all tried it to no avail.

  • @redactedsociety
    @redactedsociety Před 9 měsíci +1

    i love Fliper Zero!!!

  • @bigshoot0720
    @bigshoot0720 Před 5 měsíci

    What file do you run to get the keylogger?

  • @the-real-random-person
    @the-real-random-person Před 9 měsíci

    Its crazy! (Please tell me what betterdiscord theme it is 😭 its beautiful)
    b64 is not the best encoding way you could do, i suggest more doing something AES or something lile that. You could simply put it in a python script and you have the entire system

  • @OneAndOnlyZekePolaris
    @OneAndOnlyZekePolaris Před 9 měsíci

    It does not stay open for me at all. Even after using Set-Execution

  • @OneAndOnlyZekePolaris
    @OneAndOnlyZekePolaris Před 9 měsíci

    Is that script only for Windows 11?

  • @ghstdata6223
    @ghstdata6223 Před 3 měsíci +1

    So, my wife made her own key loggers for the flipperzero and its kinda scary

    • @RightMath
      @RightMath Před 8 dny

      send me the ducky script blud

  • @kimptonmachipisa4786
    @kimptonmachipisa4786 Před 5 měsíci

    Where can I find these payloads?

  • @HellHound___0
    @HellHound___0 Před měsícem

    Can we use these scripts just for a normal badusb

  • @joea361
    @joea361 Před 2 měsíci +1

    windows 11 now catches the keylogger, They are working on a update tho.

  • @lamaobscur2062
    @lamaobscur2062 Před 9 měsíci +1

    Hey i want to create another admin account with a badusb script but i want to know if the bad usb can bypass the admin password? Thx

    • @InfoSecREDD
      @InfoSecREDD Před 9 měsíci

      It is very possible. Not saying how tho. 😉

  • @molotov5000
    @molotov5000 Před 9 měsíci

    great

  • @auburnturner5
    @auburnturner5 Před 9 měsíci +2

    Do you know how to capture rolling code and decode it and then emulator on sub GHz

  • @MrBlitzz69
    @MrBlitzz69 Před 3 měsíci +1

    Hak5 payloads are compatible with the flipper zero?

  • @squinkie9388
    @squinkie9388 Před 9 měsíci +1

    What you get from the vault box?

    • @TalkingSasquach
      @TalkingSasquach  Před 9 měsíci +1

      Haven't unboxed it yet! I'll be doing that in the next couple days, gonna film it for a video!

  • @Mabulon
    @Mabulon Před 8 měsíci

    how do i plug it in

  • @HunnyBunny-nh5jt
    @HunnyBunny-nh5jt Před 6 měsíci

    I wish I could get my flipper to do this I already tried wey to many times this wey but no luck from my side

  • @MaskedPanda.
    @MaskedPanda. Před 9 měsíci +1

    nothing comes up when i drag and drop the hello world to the flipper

  • @deputy8271
    @deputy8271 Před 4 měsíci

    when i drop it nothing pops up

  • @iyeetsecurity922
    @iyeetsecurity922 Před 9 dny

    *Is the code still a secret?*

  • @Takeachance-ek2pc
    @Takeachance-ek2pc Před 9 měsíci

    That sweet let me talk to red

  • @justindolan9208
    @justindolan9208 Před 9 měsíci

    How are you able to send to your own discord?

  • @tomromano3757
    @tomromano3757 Před 5 měsíci

    i can't understand where can i find the second script

  • @Crunchypnutbutter
    @Crunchypnutbutter Před 9 měsíci +1

    Logs? What about deforestation?

  • @kemgod412
    @kemgod412 Před 4 měsíci

    Got a brand new flipper I don't want

  • @cheese_wierdo_maxwildthing42

    Yo, y u call your pc the Chupacabra??? It should be called the sasquatch cave

  • @ytprmwh3147
    @ytprmwh3147 Před 9 měsíci

    Is there any similar or same keylogger code github?

  • @OneAndOnlyZekePolaris
    @OneAndOnlyZekePolaris Před 9 měsíci

    Is it legal to use on a scammer that deserves to be behind bars?

    • @lycheefrost625
      @lycheefrost625 Před 9 měsíci +1

      Completely 😉

    • @OneAndOnlyZekePolaris
      @OneAndOnlyZekePolaris Před 9 měsíci

      @@lycheefrost625 I thought so, some idiot started attacking me because a hacker shut down a site for hacking discord users and the fact that they failed to look on CZcams because so many channels does nothing but hacking scammers 24/7 and they never got in trouble for it. And they call me a 12 year old, if I was 12 then that would make me 3 years old when I made this account. People are stupid sometimes. Makes me glad I don't count my self as a person or even human.

  • @kapzvara5732
    @kapzvara5732 Před 7 měsíci

    Very dangerous bad usb or sure

  • @717gbaby
    @717gbaby Před 12 dny

    Your video and Jacoby videos are two different videos

  • @tilleulenspiegel660
    @tilleulenspiegel660 Před 7 měsíci

    bro....less cocaine more ADHD medication

  • @prototype9000
    @prototype9000 Před 2 měsíci

    people in the commentshave no idea what they are talking about

  • @shaynekielmann-kn2tx
    @shaynekielmann-kn2tx Před 9 měsíci

    Man I'm locked out my Mac sasquatch please help me dude

  • @OneAndOnlyZekePolaris
    @OneAndOnlyZekePolaris Před 9 měsíci

    Google is so terrible.... My god it doesn't even know what -noexit means.

  • @h-t.p.24
    @h-t.p.24 Před měsícem

    Love you content but the Bill and ted hand movements from a grown man makes things unwatchable!

  • @lionheart7008
    @lionheart7008 Před 5 měsíci

    none of them are working ... useless flipper