Advanced USB HID Remote Wi-Fi Ducky Payload Injector for M5Stack StickS3
βββββββ βββββββ βββββββ βββ ββββββββββββββββββ βββ βββ ββββββββββ βββ
βββββββββββββββββββββββββ βββ ββββββββββββββββββββββ ββββββββββββββ ββββ
βββββββββββ ββββββ βββββββ βββββββββ βββ ββββββ ββββββ βββββββ
βββββββββββ ββββββ ββββββ βββββββββ βββ ββββββ ββββββ βββββββ
βββ ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ βββ
βββ βββ βββββββ βββββββ βββββββ βββββββββββββββ βββββββ ββββββββββ βββ
ROGUEDUCK V2.1 is a custom, tactical firmware that transforms the M5Stack StickS3 into a covert, dual-network BadUSB tool. It features a complete mobile-first web interface, on-the-fly DuckyScript parsing, cloud-payload fetching, and a cyberpunk CRT hardware UI.
- Station Mode (STA): Automatically attempts to connect to a predefined mobile hotspot or local network for internet-enabled attacks.
- Access Point (AP) Fallback: Always broadcasts its own isolated
RogueDuck_Syncnetwork so you are never locked out of the command center. - Captive Portal: A built-in DNS server in AP mode intercepts network traffic, forcing the connecting device's web browser to automatically pop up the Command Center.
- Global Cloud Tunneling: Includes a Python companion script (
rogueduck_tunnel.py) to bridge the local M5Stack to the internet via Cloudflare or Ngrok, allowing you to control the device and trigger payloads from anywhere in the world.
A stealthy, dark-mode web application optimized for fat-thumb operation on smartphones.
- Over-The-Air Uploads: Push
.txtDuckyScript payloads directly to internal storage (LittleFS). - Live Editor: Write, edit, and save payloads directly from your mobile browser.
- Cloud Vector Deployment: Paste a raw URL (e.g., GitHub Raw, Pastebin) to fetch and execute a payload entirely in RAM, leaving no trace on the device's physical storage.
- Remote Execution: Trigger any stored payload instantly from the web app.
- Panic Wipe: A dedicated killswitch at the bottom of the UI that formats the LittleFS partition, permanently wiping all stored payloads in seconds.
- Tactical Data Exfiltration: Securely transmit stolen data (passwords, keys, tokens) from the target machine directly to the RogueDuck via
Invoke-RestMethod. Stored loot is centralized, viewable in the web UI, and manageable in real-time. - Loot Management: A dedicated dashboard to view, ignore, or perform a mass wipe of exfiltrated data files with a single click.
- Cyberpunk CRT Aesthetic: Simulated CRT scanlines, dynamic glitch effects during injection, and dynamic IP rendering.
- Pocket Lock & Battery Saver: Long-press the side button to dim the screen and disable the physical injection buttons, preventing accidental misfires in your pocket.
- Live Telemetry: Real-time battery percentage monitoring directly on the header.
| Device Hardware | File & Cloud Operations |
|---|---|
![]() |
![]() |
| Cyberpunk CRT Hardware UI | Cloud Vector & Local Storage |
| Payload Creation | Tactical Exfiltration |
|---|---|
![]() |
![]() |
| OTA DuckyScript Editor | Loot Dashboard & Network Setup |
- Device: M5Stack StickS3 - Product Docs/Purchase: M5Stack StickS3 (ESP32-S3)
- Connection: USB-C (For flashing and HID emulation)
If you Don't want to mess with code, and enjoy its beauty, you can just download the latest .bin files.
- M5Stack M5Burner - View Download And Docs Here!
- M5Launcher By bmorcelli - Github: View Source Here! - Web: Flash Firmware Here!
Ensure you have the following libraries installed in the Arduino IDE:
M5UnifiedLittleFSUSBUSBHIDKeyboardHTTPClientWebServer
Unlike previous builds, Wi-Fi Station configurations no longer need to be hard-coded into the source code before compilation.
- Flash the firmware using the instructions below.
- Power on the device. It will spin up the
RogueDuck_SyncAccess Point automatically. - Connect your smartphone to the network
defult password: 12345678and allow the Captive Portal to load, or visithttp://192.168.4.1/. - Scroll to the Wi-Fi Configuration section at the bottom, input your permanent hotspot credentials Eg. Your mobile hotspot. and select SAVE & REBOOT.
Because this firmware utilizes heavy web assets, dual Wi-Fi, and HTTP clients, it exceeds the default 1.2MB ESP32 application limit.
- In Arduino IDE, navigate to Tools > Partition Scheme.
- Select Huge APP (3MB No OTA/1MB SPIFFS) or No OTA (2MB APP/2MB SPIFFS).
- Compile and Upload.
- Button A (Front):
INJECT PAYLOAD- Executes the currently selected payload. - Button B (Side Short-Click):
SCROLL- Cycles through stored payloads. - Button B (Side Long-Press):
POCKET LOCK- Toggles the battery-saver dim mode and locks the physical execution buttons.
- Connect your smartphone/PC to either the
RogueDuck_SyncWi-Fi network OR the configured Hotspot network. - Check the M5StickS3's physical screen for the assigned IP Address.
- Enter the IP into your web browser.
- Use the GUI to upload, edit, fire, view loot, or wipe payloads.
The internal parser processes standard US-English layout DuckyScript 1.0 commands:
STRING/STRINGLNDELAY/DEFAULT_DELAYGUI/WINDOWS/COMMANDCTRL,SHIFT,ALT(and combos likeCTRL-ALT-DELETE)ENTER,TAB,SPACE,ESC,UP,DOWN,LEFT,RIGHTF1-F12REM(Comments)REPEAT
-
Captive Portal: Implement a DNS server in AP mode so connecting to the RogueDuck_Sync Wi-Fi automatically opens the Web UI.
-
Tunneling Companion Guide: Add documentation and a companion Python script for setting up Ngrok/Cloudflare reverse tunneling for global access.
-
Data Exfiltration: Add a listener endpoint to capture keystrokes or data from the target machine and save it to LittleFS.
-
International Keyboard Layouts: Expand character mapping beyond US English to support UK, DE, FR, and ES layouts.
-
Onboard SD Card Storage: Integrate support for external SD hardware configurations.
-
Stealth Mode (Screen Masking): Implement a "Set-and-Forget" UI toggle to replace active terminal visuals with a deceptive, low-power "Office/Admin" screen saver to ensure physical concealment during deployments.
At roughly $20 USD, the M5StickS3 isn't just a development board; it is a high-performance, cost-effective force multiplier for penetration testing. Its compact form factorβresembling a common USB thumb drive or a portable media controllerβallows it to blend into almost any professional environment without drawing a second glance.
The deviceβs true strength lies in its ability to facilitate "set-and-forget" deployments while providing reliable wireless command and control. Because it is powered by the ESP32-S3, it offers native HID (Human Interface Device) capabilities, allowing it to act as a malicious keyboard, while the integrated Wi-Fi and Bluetooth radios provide a discreet, long-range management channel.
- Server Room/Data Center Surveillance: In a server room environment, the M5StickS3 can be attached to the rear of a rack-mounted server or a KVM switch using double-sided tape. Because of its tiny footprint, it disappears into the existing cable management and hardware clutter. Once connected, it can be left to periodically beacon out status updates or await commands, effectively turning a forgotten port into a persistent remote access point.
- Office Environment Persistence: In a standard office setting, the device can be plugged into the rear USB port of a target workstation or a VOIP phone. To any passerby or IT auditor, the small, glowing display is easily mistaken for a common USB receiver or a peripheral component. By masquerading as a benign piece of hardware, it maintains a persistent, low-profile foothold on the target machine, ready to execute payloads the moment the user logs in.
Whether you are performing a controlled physical assessment or testing the vigilance of on-site security, the M5StickS3 provides the perfect balance of budget, stealth, and technical capability.
**ROGUEDUCK V2.1 by @M5RogueOps** **Powered by Ethical Hackers Den**
This tool is designed for educational purposes, authorized penetration testing, and personal research. The developers assume no liability and are not responsible for any misuse or damage caused by this firmware. Only operate on networks and devices you have explicit permission to test.



