Skip to content

M5RogueOps/M5StickS3-RogueDuck

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

74 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸ¦† ROGUEDUCK V2.1 (Now Be Free My Precious)

Advanced USB HID Remote Wi-Fi Ducky Payload Injector for M5Stack StickS3

 β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—  β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—  β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ•—   β–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ•—   β–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•—  β–ˆβ–ˆβ•—
 β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ•”β•β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ•”β•β•β•β•β• β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β•β•β•β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β•β•β•β–ˆβ–ˆβ•‘ β–ˆβ–ˆβ•”β•
 β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—  β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘     β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β• 
 β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β•  β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘     β–ˆβ–ˆβ•”β•β–ˆβ–ˆβ•— 
 β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β•šβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•β•šβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•β•šβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•β•šβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•β•šβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•—
 β•šβ•β•  β•šβ•β• β•šβ•β•β•β•β•β•  β•šβ•β•β•β•β•β•  β•šβ•β•β•β•β•β•  β•šβ•β•β•β•β•β•β•β•šβ•β•β•β•β•β•  β•šβ•β•β•β•β•β•  β•šβ•β•β•β•β•β•β•šβ•β•  β•šβ•β•

ROGUEDUCK V2.1 is a custom, tactical firmware that transforms the M5Stack StickS3 into a covert, dual-network BadUSB tool. It features a complete mobile-first web interface, on-the-fly DuckyScript parsing, cloud-payload fetching, and a cyberpunk CRT hardware UI.


πŸš€ Key Features

🌐 Dual-Mode Networking (AP + STA)

  • Station Mode (STA): Automatically attempts to connect to a predefined mobile hotspot or local network for internet-enabled attacks.
  • Access Point (AP) Fallback: Always broadcasts its own isolated RogueDuck_Sync network so you are never locked out of the command center.
  • Captive Portal: A built-in DNS server in AP mode intercepts network traffic, forcing the connecting device's web browser to automatically pop up the Command Center.
  • Global Cloud Tunneling: Includes a Python companion script (rogueduck_tunnel.py) to bridge the local M5Stack to the internet via Cloudflare or Ngrok, allowing you to control the device and trigger payloads from anywhere in the world.

πŸ“± Mobile-First Web Command Center

A stealthy, dark-mode web application optimized for fat-thumb operation on smartphones.

  • Over-The-Air Uploads: Push .txt DuckyScript payloads directly to internal storage (LittleFS).
  • Live Editor: Write, edit, and save payloads directly from your mobile browser.
  • Cloud Vector Deployment: Paste a raw URL (e.g., GitHub Raw, Pastebin) to fetch and execute a payload entirely in RAM, leaving no trace on the device's physical storage.
  • Remote Execution: Trigger any stored payload instantly from the web app.
  • Panic Wipe: A dedicated killswitch at the bottom of the UI that formats the LittleFS partition, permanently wiping all stored payloads in seconds.
  • Tactical Data Exfiltration: Securely transmit stolen data (passwords, keys, tokens) from the target machine directly to the RogueDuck via Invoke-RestMethod. Stored loot is centralized, viewable in the web UI, and manageable in real-time.
  • Loot Management: A dedicated dashboard to view, ignore, or perform a mass wipe of exfiltrated data files with a single click.

πŸ“Ÿ Hardware Interface

  • Cyberpunk CRT Aesthetic: Simulated CRT scanlines, dynamic glitch effects during injection, and dynamic IP rendering.
  • Pocket Lock & Battery Saver: Long-press the side button to dim the screen and disable the physical injection buttons, preventing accidental misfires in your pocket.
  • Live Telemetry: Real-time battery percentage monitoring directly on the header.

πŸ“Έ Interface Overview

Device Hardware File & Cloud Operations
Hardware UI Payload Management
Cyberpunk CRT Hardware UI Cloud Vector & Local Storage
Payload Creation Tactical Exfiltration
Web Editor Exfiltration Dashboard
OTA DuckyScript Editor Loot Dashboard & Network Setup

πŸ› οΈ Hardware Requirements


βš™οΈ Installation & Flashing

If you Don't want to mess with code, and enjoy its beauty, you can just download the latest .bin files.

1. Dependencies

Ensure you have the following libraries installed in the Arduino IDE:

  • M5Unified
  • LittleFS
  • USB
  • USBHIDKeyboard
  • HTTPClient
  • WebServer

2. Configuration & First-Boot

Unlike previous builds, Wi-Fi Station configurations no longer need to be hard-coded into the source code before compilation.

  1. Flash the firmware using the instructions below.
  2. Power on the device. It will spin up the RogueDuck_Sync Access Point automatically.
  3. Connect your smartphone to the network defult password: 12345678 and allow the Captive Portal to load, or visit http://192.168.4.1/.
  4. Scroll to the Wi-Fi Configuration section at the bottom, input your permanent hotspot credentials Eg. Your mobile hotspot. and select SAVE & REBOOT.

3. CRITICAL: Partition Scheme

Because this firmware utilizes heavy web assets, dual Wi-Fi, and HTTP clients, it exceeds the default 1.2MB ESP32 application limit.

  • In Arduino IDE, navigate to Tools > Partition Scheme.
  • Select Huge APP (3MB No OTA/1MB SPIFFS) or No OTA (2MB APP/2MB SPIFFS).
  • Compile and Upload.

πŸ•ΉοΈ Operation Guide

Physical Controls

  • Button A (Front): INJECT PAYLOAD - Executes the currently selected payload.
  • Button B (Side Short-Click): SCROLL - Cycles through stored payloads.
  • Button B (Side Long-Press): POCKET LOCK - Toggles the battery-saver dim mode and locks the physical execution buttons.

Web Controls

  1. Connect your smartphone/PC to either the RogueDuck_Sync Wi-Fi network OR the configured Hotspot network.
  2. Check the M5StickS3's physical screen for the assigned IP Address.
  3. Enter the IP into your web browser.
  4. Use the GUI to upload, edit, fire, view loot, or wipe payloads.

πŸ“œ Supported DuckyScript 1.0 Syntax

The internal parser processes standard US-English layout DuckyScript 1.0 commands:

  • STRING / STRINGLN
  • DELAY / DEFAULT_DELAY
  • GUI / WINDOWS / COMMAND
  • CTRL, SHIFT, ALT (and combos like CTRL-ALT-DELETE)
  • ENTER, TAB, SPACE, ESC, UP, DOWN, LEFT, RIGHT
  • F1 - F12
  • REM (Comments)
  • REPEAT

πŸ“‹ To-Do / Roadmap

  • Captive Portal: Implement a DNS server in AP mode so connecting to the RogueDuck_Sync Wi-Fi automatically opens the Web UI.

  • Tunneling Companion Guide: Add documentation and a companion Python script for setting up Ngrok/Cloudflare reverse tunneling for global access.

  • Data Exfiltration: Add a listener endpoint to capture keystrokes or data from the target machine and save it to LittleFS.

  • International Keyboard Layouts: Expand character mapping beyond US English to support UK, DE, FR, and ES layouts.

  • Onboard SD Card Storage: Integrate support for external SD hardware configurations.

  • Stealth Mode (Screen Masking): Implement a "Set-and-Forget" UI toggle to replace active terminal visuals with a deceptive, low-power "Office/Admin" screen saver to ensure physical concealment during deployments.


Why the M5StickS3 is the Ultimate Red Team Tool

At roughly $20 USD, the M5StickS3 isn't just a development board; it is a high-performance, cost-effective force multiplier for penetration testing. Its compact form factorβ€”resembling a common USB thumb drive or a portable media controllerβ€”allows it to blend into almost any professional environment without drawing a second glance.

Unmatched Stealth and Versatility

The device’s true strength lies in its ability to facilitate "set-and-forget" deployments while providing reliable wireless command and control. Because it is powered by the ESP32-S3, it offers native HID (Human Interface Device) capabilities, allowing it to act as a malicious keyboard, while the integrated Wi-Fi and Bluetooth radios provide a discreet, long-range management channel.

Tactical Use Cases

  • Server Room/Data Center Surveillance: In a server room environment, the M5StickS3 can be attached to the rear of a rack-mounted server or a KVM switch using double-sided tape. Because of its tiny footprint, it disappears into the existing cable management and hardware clutter. Once connected, it can be left to periodically beacon out status updates or await commands, effectively turning a forgotten port into a persistent remote access point.
  • Office Environment Persistence: In a standard office setting, the device can be plugged into the rear USB port of a target workstation or a VOIP phone. To any passerby or IT auditor, the small, glowing display is easily mistaken for a common USB receiver or a peripheral component. By masquerading as a benign piece of hardware, it maintains a persistent, low-profile foothold on the target machine, ready to execute payloads the moment the user logs in.

Whether you are performing a controlled physical assessment or testing the vigilance of on-site security, the M5StickS3 provides the perfect balance of budget, stealth, and technical capability.

πŸ›‘οΈ Credits & Disclaimer

**ROGUEDUCK V2.1 by @M5RogueOps** **Powered by Ethical Hackers Den**

This tool is designed for educational purposes, authorized penetration testing, and personal research. The developers assume no liability and are not responsible for any misuse or damage caused by this firmware. Only operate on networks and devices you have explicit permission to test.



About

ROGUEDUCK V2.1 - A DuckyScript USB Payload Injector For The M5Stack StickS3

Topics

Resources

Stars

4 stars

Watchers

1 watching

Forks

Packages

 
 
 

Contributors