🏆 by Cribbit September 18, 2022
General USB Rubber Ducky
Little arcade coin drop / pachinko style game.
🏆 by drapl0n September 01, 2022
Bash Bunny Credentials
BunnyLogger is a Key Logger which captures every key stroke of target and send them to attacker.
🏆 by Cribbit September 01, 2022
Exfiltration USB Rubber Ducky
Proof of concept for send an image over key reflection using two methods of converting bytes to key presses.
🏆 by atomiczsec August 30, 2022
Exfiltration OMG
This payload will enumerate through the browser directories, looking for the file that stores the bookmark history These files will be saved to the temp dire...
🏆 by ph3llin August 30, 2022
Exfiltration USB Rubber Ducky
GRABS ALL WIFI PASSWORDS ON WINDOWS CREATES log.txt ON DESKTOP THEN UPLOADS TO YOUR DROPBOX MUST EDIT DROP BOX TOKEN BELOW
🏆 by TW-D August 30, 2022
OMG Remote Access
1. Adds a user account (OMG_User:OMG_P@ssW0rD).
2. Adds this local user to local administrator group.
3. Enables "Windows Remote Management" with default set...
🏆 by Carey Balboa August 30, 2022
Bash Bunny Exfiltration
Exfiltrates files from logged in users Documents and Desktop folders.
🏆 by Lumen August 17, 2022
Recon USB Rubber Ducky
Downloads program in a zip file, then unzips and executes it.
🏆 by MocconaCoffee July 14, 2022
Prank USB Rubber Ducky
A simple script that will load a fake Windows 10 update screen, and begin to rick roll the target at 100% volume and will continuously raise the volume back ...
🏆 by LulzAnarchyAnon July 14, 2022
Execution OMG
Administrator PowerShell is opened, and a script runs that adds a Local Admin User.
🏆 by DanTheGoodman July 14, 2022
Bash Bunny Exfiltration
A stupid easy to use file extractor leveraging the USB storage attack mode. Will stuff the found files in the /loot/simple-usb-file-extractor folder. Also de...
🏆 by 0iphor13 June 09, 2022
Bash Bunny Credentials
SamDumpBunny dumps the users sam and system hive and compresses them into a zip file. Afterwards you can use a tool like samdump2 to extract the users hashes.
🏆 by drapl0n June 09, 2022
Execution Shark Jack
SharkDOS payload intelligently scan target's network for open http (configurable for https) ports and DOS it.
🏆 by Cribbit June 09, 2022
Bash Bunny Prank
Converts Jpeg, Png & BMP's in the My Pictures to ascii art versions.
🏆 by PanicAcid June 01, 2022
Bash Bunny Execution
Executes code leveraging CVE-2022-30190 aka Follina using a malicious html file hosted on the Bunny itself. Whilst this exploit can be called via a malicious...
🏆 by LulzAnarchyAnon June 01, 2022
Bash Bunny Prank
The webcam is opened, and 15 pictures are taken and saved to the camera roll folder. The wallpaper settings are then changed so the Photos/Camera Roll folder...
🏆 by LulzAnarchyAnon May 29, 2022
Execution OMG
This is a Three stage payload that begins by opening bluetooth file transfer on the target device. Next the attackers bluetooth adapter name is selected for...
🏆 by thisismyrobot May 29, 2022
Exfiltration USB Rubber Ducky
A script to exfiltrate Chrome browser credentials from a target. Entered interactively to bypass a lot of PowerShell-related AV triggers. The Chrome GET requ...