PlunderPIN

PlunderPIN
Download Copy
Title: PlunderPIN
Author: OSINTI4L

PlunderPIN is a mobile PIN phishing payload that replaces a user's Google Chrome browser homepage with a malicious imitation homepage that creates prompts to capture the user's PIN and log it to a self hosted Apache webserver.

🏆   Recognized with a Payload Award in January 2026

 

This payload is for the USB Rubber Ducky — a "flash drive" that types keystroke injection payloads into unsuspecting computers at incredible speeds. It's no wonder this little quacker has made appearances on Mr. Robot, FBI, Blacklist, National Geography and more!

Submit your own payload, or browse more featured USB Rubber Ducky Payloads.

 

 

Related Payloads

Mobile2GPS
Mobile2GPS
A payload for the Hak5 WiFi Pineapple Pager that lets you use your mobile phone as the Pager's GPS.
Read More
Evil Portal
Evil Portal
A complete Evil Portal implementation for the WiFi Pineapple Pager, including captive portal detection and credential ca
Read More
Passpoint Scanner
Passpoint Scanner
Scanner for true Passpoint/Hotspot 2.0 networks. Detects Passpoint APs via IE 221 (HS2.0 Vendor Specific OUI 50:6f:9a:10
Read More