Duckie Harvest

Duckie Harvest
Download Copy
Title: Duckie Harvest
Author: NiK0-Byt3

This payload extracts and saves Wi-Fi passwords and browser credentials from Google Chrome, Brave, Firefox, and Microsoft Edge on the target machine. Additionally, it collects comprehensive system information, including network configurations and active processes, performs a network scan, and can initiate a reverse shell for remote command-line access.

🏆   Recognized with a Payload Award in February 2025

 

Credential harvesting is the method of obtaining credentials — think usernames and passwords. Many techniques are used to obtain credentials, from keylogging to credential dumping. With a set of credentials in hand, red teamers may access systems and make lateral movement across the network, as well as creating their own credentials which may be difficult to detect in a breach. See all credential payloads.

This payload is for the USB Rubber Ducky — a "flash drive" that types keystroke injection payloads into unsuspecting computers at incredible speeds. It's no wonder this little quacker has made appearances on Mr. Robot, FBI, Blacklist, National Geography and more!

Submit your own payload, or browse more featured USB Rubber Ducky Payloads.

 

 

Related Payloads

USB Poison
USB Poison
This payload executes a script that waits for new USB flash storage devices to be connected. When a new device connects,
Read More
Execute commands as NT AUTHORITY\SYSTEM with TrustedInstaller privileges
Execute commands as NT AUTHORITY\SYSTEM with TrustedInstaller privileges
This payload launches a new cmd.exe process with elevated privileges under TrustedInstaller, by setting the TrustedInsta
Read More
Blind OS Command Injection using Serial Number
Blind OS Command Injection using Serial Number
This payload allows a remote attacker to execute commands on a Linux system using the serial number as a vector to pass
Read More