This script can be used play a prank on friends by having them follow an Instagram account.
Open a PowerShell, start a process trough the default browser th...
Exfilter all the images from the principal folders on unlocked MacOS targets. Stashes them in /loot/MacDocsExfill
Get password for logged-in user and unlock machine. Based on quickcreds and win10lockpicker.
Get a bunch of delicious data from unlocked macOS devices.
Capture target E-mail address & password save to /udisk/tools/target_email.txt
This is the first of the iOS 2.0 Payloads, this payload will go and create a shortcut that runs automatically without notifying the user, iOS 2.0 allows for ...
Makes packet Squirrel directly accessible via SSH on a remote server.
Uses the "Microsoft Edge" web browser to search for web servers within a range of IPv4 addresses that do not have an "X-Frame-Options" header.
Then exports ...
Get Windows "powershell" or MacOS "say" or Linux (ubuntu) "espeak" to speak the opening of the duck song
Downloads a picture and set it as wallpaper, gets Visible after Restart or Relogin
Attempt to connect Keycroc automatically to target wifi access point
A lil' prank for all the ones snooping on your usb sticks. This will lock the machine every 100ms until the button is pressed (or ther ducky pulled out)
This payload exfiltrates Windows system information and installed programs from the target computer to Dropbox cloud storage for subsequent privilege escalat...
ReverseDuckyUltimate (RDU) takes the best of every ReverseDucky payload. Customization, encryption, indentifiers, multi-layer polymorphism and automatic setu...
Triggered_Bunny covertly executes phishing page on remote triggers.
Reads all txt files in "my documents" and flashes the scroll lock on and off to represent Morse code of the English alphanumeric characters (0..9 A..Z)
This payload is meant to exfiltrate bash history to a dropbox