The USB Rubber Ducky is the original keystroke injection tool by Hak5. Recognized by computers as a keyboard, it can inject pre-programmed keystrokes at superhuman speeds. DuckyScript 1.0 payloads are backwards compatible with DuckyScript 3.0.
REM Hello World Example Script
DELAY 1000
GUI r
DELAY 500
STRING notepad
ENTER
DELAY 1000
STRING Hello from USB Rubber Ducky!
REM DuckyScript 3.0 supports variables:
VAR $COUNT = 0
WHILE ($COUNT < 5)
STRINGLN Iteration $COUNT
$COUNT = ($COUNT + 1)
END_WHILE
Flipper Zero is a portable multi-tool for pentesters and geeks. It includes BadUSB functionality that allows it to act as a USB keyboard and execute pre-programmed scripts. The BadUSB feature uses DuckyScript 1.0 syntax with Flipper-specific extensions like ALT+Numpad and SysRq commands.
Key features
Built-in screen for payload selection
Bluetooth and IR capabilities
Sub-GHz radio for RF analysis
NFC and RFID support
GPIO pins for hardware hacking
MicroSD expandable storage
Firmware updates via qFlipper
Active community and payload library
example payload · DuckyScript 1.0 (with Flipper extensions)
REM Flipper Zero BadUSB Script
ID 1234:5678 Flipper Keyboard
DELAY 1000
GUI r
DELAY 500
STRING powershell
CTRL-SHIFT ENTER
DELAY 1500
ALT y
DELAY 1000
STRING Write-Host "Hello from Flipper Zero!"
ENTER
Evil Crow Cable Wind is a BadUSB device based on ESP32-S3 disguised as a USB cable. It can be controlled via a web panel over WiFi. Uses Wind Syntax with commands like Print, PrintLine, Press KEY_ENTER, Delay, GuiR, and more.
Key features
Looks like a normal USB cable
ESP32-S3 based with WiFi control
Web panel at http://cable-wind.local/
Multiple keyboard layout support (18 layouts)
Payload editor with syntax checker
OS detection capability
AutoExec planning
Remote shell (Linux/iOS/Windows/Android)
WinPrint/WinPrintLine for unknown layouts
Wind Syntax scripting language
example payload · Wind Syntax
REM Evil Crow Cable Wind Payload
REM Wind Syntax Commands:
REM - Print <text> - types text
REM - PrintLine <text> - types text + Enter
REM - Press KEY_ENTER - press Enter key
REM - Press KEY_TAB - press Tab key
REM - Delay <ms> - wait in milliseconds
REM - GuiR - Windows+R (Run dialog)
REM - Gui - Windows key
REM - CtrlAltT - Ctrl+Alt+T (Linux terminal)
REM - Press KEY_LEFT_CTRL - Ctrl key
REM - Press KEY_LEFT_ALT - Alt key
REM - WinPrint/WinPrintLine - for unknown layouts
REM
REM === Windows Example ===
Delay 2000
GuiR
Delay 500
PrintLine cmd
Delay 1000
PrintLine echo Evil Crow Cable Wind Active!
Press KEY_ENTER
REM
REM === Linux Example ===
REM Delay 2000
REM CtrlAltT
REM Delay 500
REM PrintLine echo Hello from Evil Crow!
REM Press KEY_ENTER
REM
REM === WinPrint for unknown layouts (Windows only) ===
REM WinPrintLine Hello World!@#/()-:,;0123456789
The Bash Bunny is a multi-function USB attack platform by Hak5. It's a quad-core Linux computer that can emulate trusted USB devices like keyboards, serial ports, storage, and Ethernet adapters to deliver advanced payloads.
Key features
Quad-core Linux computer
Multi-vector USB attacks
HID keyboard emulation
Ethernet adapter emulation (RNDIS/ECM)
Mass storage emulation
Serial console access
RGB LED status indicators
Physical switch for payload selection (3 positions)
Extensions system for enhanced payloads
example payload · Bunny Script (DuckyScript + Bash)
#!/bin/bash
# Bash Bunny Payload
LED SETUP
ATTACKMODE HID STORAGE
DUCKY_LANG us
LED ATTACK
QUACK GUI r
QUACK DELAY 500
QUACK STRING powershell
QUACK ENTER
QUACK DELAY 1000
QUACK STRING "Write-Host 'Bash Bunny Active'"
QUACK ENTER
LED FINISH
USB Nova is a BadUSB device by Spacehuhn. It's compatible with DuckyScript 1.0 with some functions added or expanded. Features include mouse support, multiple modes with LED colors, and firmware update capability.
Key features
DuckyScript 1.0 compatible
Additional functions and keys
Mouse support
Multiple modes with LED colors
Firmware update capability
DIY tutorial available
Compact form factor
Cross-platform support
example payload · DuckyScript 1.0 (with extensions)
REM USB Nova Hello World Script
REM Compatible with DuckyScript 1.0
DEFAULTDELAY 200
DELAY 1000
GUI r
STRING notepad
ENTER
DELAY 1000
STRING Hello from USB Nova!
REM USB Nova supports mouse commands:
REM MOUSE MOVE 100 50
REM MOUSE CLICK LEFT
Malduino is a BadUSB device by Maltronics. Writing scripts is based on DuckyScript syntax and can be learned in minutes. Supports multiple keyboard locales and features like REPEAT command and configurable key press delays.
example payload · DuckyScript (Maltronics variant)
REM Malduino Payload
LOCALE US
DELAY 1000
GUI r
STRING notepad
ENTER
DELAY 500
STRING It's super easy to script for MalDuino!
REM Repeat previous command 3 times:
REM REPEAT 3
REM Set default delay:
REM DEFAULTDELAY 100
REM Set key press duration:
REM KEYPRESS_DELAY 10
Key Croc is a keylogger armed with pentest tools. It captures keystrokes and can inject payloads based on pattern matching. Native commands (MATCH, SAVEKEYS, LED) don't need Q prefix; DuckyScript commands (STRING, DELAY, GUI) need QUACK prefix.
Key features
Keylogger with cloud sync
Pattern matching with MATCH command
SAVEKEYS for capturing credentials
WiFi connectivity for remote access
Payload injection on trigger
USB passthrough mode
LED status indicators
MicroSD storage
example payload · DuckyScript 2.X (with Key Croc extensions)
# Key Croc Payload - Capture passwords after keyword
MATCH password
SAVEKEYS /root/loot/creds.txt NEXT 20
LED ATTACK
WAIT_FOR_LOOT /root/loot/creds.txt
LED FINISH
# Inject keystrokes on trigger
MATCH admin
QUACK GUI r
QUACK DELAY 500
QUACK STRING cmd
QUACK ENTER
O.MG Cable looks like a regular USB cable but contains a hidden implant for keystroke injection and WiFi-based remote access. Supports 191 keyboard layouts via DUCKY_LANG, mouse emulation, geofencing, and randomization commands. Connect to WiFi (SSID: O.MG, Pass: 12345678) and browse to 192.168.4.1.
Key features
Looks like genuine USB cable
WiFi-based remote control (192.168.4.1)
191 keyboard layouts (DUCKY_LANG)
Mouse emulation (MOUSE MOVE/CLICK)
Randomization commands (RANDOM_CHAR, etc.)
Geofencing (IF_PRESENT, WAIT_FOR_PRESENT)
Self-destruct feature
Jiggler mode to prevent screen lock
example payload · DuckyScript (O.MG Extensions)
REM O.MG Cable Payload with Extensions
DUCKY_LANG US
DEFAULT_DELAY 100
REM Move mouse to corner and click
MOUSE MOVE -10000 -10000
MOUSE CLICK 1
DELAY 1000
GUI r
DELAY 500
STRING powershell -w hidden
ENTER
DELAY 1000
REM Generate random password
STRING $pass = "
REPEAT 16 RANDOM_CHAR
STRINGLN "
REM Jiggler to prevent screen lock
JIGGLER ON
Packet Squirrel is a stealthy pocket-sized man-in-the-middle device. It can capture network traffic, perform DNS spoofing, and execute payloads. Uses DuckyScript with NETMODE, LED, and BUTTON commands.
Key features
Man-in-the-middle attacks
Packet capture to USB storage
DNS spoofing
VPN tunneling
Payload switching via button
LED status indicators
Ethernet passthrough
Remote access via reverse SSH
example payload · DuckyScript (Packet Squirrel)
#!/bin/bash
# Packet Squirrel Payload - Traffic Capture
LED SETUP
NETMODE TRANSPARENT
# Start packet capture
LED ATTACK
tcpdump -i br-lan -w /mnt/loot/capture.pcap &
# Wait for button press to stop
BUTTON
killall tcpdump
LED FINISH
LAN Turtle is a covert Systems Administration and Penetration Testing tool providing stealth remote access, network intelligence gathering, and man-in-the-middle monitoring capabilities. Uses a modular system with start/stop/configure functions.
Key features
Stealth USB Ethernet adapter
Remote access via autossh
Man-in-the-middle capabilities
Modular payload system
DNS spoofing
Responder integration
Meterpreter support
Cloud C2 compatible
example payload · Turtle Module (Bash)
#!/bin/bash /usr/lib/turtle/turtle_module
# LAN Turtle Module - Responder
VERSION="1.0"
DESCRIPTION="Capture NTLM hashes with Responder"
CONF=/tmp/responder.form
function start {
responder -I eth0 -wrf &
PID=$!
echo $PID > /var/run/responder.pid
}
function stop {
kill $(cat /var/run/responder.pid)
}
function status {
if pgrep responder > /dev/null; then
echo "1"
else
echo "0"
fi
}
Shark Jack is a portable network attack tool by Hak5. It's designed for quick network reconnaissance and payload delivery. Uses NETMODE for network configuration and LED commands for status indication. Payloads are stored in /root/payload/ folder.
Key features
Portable network attack tool
Nmap scanning capabilities
Payload switching via modes
LED status indicators
Internal storage for loot
Battery powered
Quick network recon
Cloud C2 compatible
example payload · DuckyScript (Shark Jack)
#!/bin/bash
# Shark Jack Payload - Network Scan
# NETMODE: DHCP_CLIENT, DHCP_SERVER, or TRANSPARENT
NETMODE DHCP_CLIENT
LED SETUP
# Wait for network connection
while ! ip addr show eth0 | grep -q "inet "; do
sleep 1
done
LED ATTACK
# Run nmap scan
nmap -sP 192.168.1.0/24 -oN /root/loot/scan.txt
LED CLEANUP
sync
LED FINISH
Digispark is a tiny, Arduino-compatible development board based on the ATtiny85 microcontroller. It can be programmed to act as a USB keyboard for keystroke injection attacks. Duckify by Spacehuhn provides a web converter to translate DuckyScript to Arduino code.
Key features
Ultra-compact size (smaller than a quarter)
ATtiny85 microcontroller
Low cost entry point
Arduino IDE compatible
6 I/O pins
Built-in USB connector
No bootloader button needed
Duckify converter for DuckyScript
example payload · Arduino (DigiKeyboard library)
#include "DigiKeyboard.h"
void setup() {
DigiKeyboard.sendKeyStroke(0);
DigiKeyboard.delay(2000);
// Open Run dialog (Windows)
DigiKeyboard.sendKeyStroke(KEY_R, MOD_GUI_LEFT);
DigiKeyboard.delay(500);
DigiKeyboard.print("notepad");
DigiKeyboard.sendKeyStroke(KEY_ENTER);
DigiKeyboard.delay(1000);
DigiKeyboard.print("Hello from Digispark!");
}
void loop() {
// Stop execution
}
The WiFi Pineapple Pager is a portable WiFi pentesting tool celebrating 20 years of WiFi exploits. It features a retro pager form factor with a vibrant display, battery power, and tri-band wireless radios. The device runs payloads written in Bash and DuckyScript, perfect for hands-free, event-driven WiFi attacks.
Key features
Standalone portable pentest device
Tri-band WiFi radios
Real-time WiFi alerts with ringtones
Battery powered operation
Menu-driven interface
GPS support for wardriving
PineAP attack suite
Recon and handshake capture
SSID impersonation pool
Cloud C2 compatible
example payload · Bash Script + DuckyScript
#!/bin/bash
# WiFi Pineapple Pager User Payload
# Scan for nearby networks and display results
PROMPT "Starting WiFi Recon"
START_SPINNER "Scanning..."
# Start a new recon session
PINEAPPLE_RECON_NEW
# Wait for scan
sleep 10
STOP_SPINNER
LOG "Scan complete!"
# Prompt for target selection
TEXT_PICKER "Enter target SSID" TARGET_SSID
# Add to SSID pool for impersonation
PINEAPPLE_SSID_POOL_ADD "$TARGET_SSID"
PINEAPPLE_SSID_POOL_START
ALERT "Evil Twin Active" "Now impersonating: $TARGET_SSID"
DuckyScript versions.
DuckyScript officially licensed devices are backwards compatible with previous versions. Payloads written for v1.0 run on v3.0 devices without modification.
Version
Devices
What it adds
v1.0
Original USB Rubber Ducky (USB-A Only), USB Nova, Flipper Zero (BadUSB), Malduino
Basic keystroke injection with simple commands. Flipper Zero uses v1.0 with custom extensions (ID, SYSRQ, ALT+Numpad). REM · DELAY · STRING · ENTER · GUI · ALT · CTRL · SHIFT · REPEAT
vWind
Evil Crow Cable Wind
Evil Crow Cable Wind uses Wind Syntax with commands like Print, PrintLine, Press KEY_ENTER, Delay, GuiR, CtrlAltT, and special WinPrint for unknown keyboard layouts. REM · Delay · Print · PrintLine · Press KEY_* · GuiR · Gui · CtrlAltT · WinPrint · WinPrintLine
v2.X
Bash Bunny, Key Croc, O.MG Devices
Extended syntax with device-specific commands. Key Croc adds MATCH and SAVEKEYS for keylogging. All v1.0 commands · ATTACKMODE · QUACK · LED · MATCH (Key Croc) · SAVEKEYS (Key Croc)
v3.0
New USB Rubber Ducky (USB-A & USB-C)
Full programming language with variables, conditions, loops, and functions. Backwards compatible with v1.0. All v1.0 commands · VAR · IF/ELSE/END_IF · WHILE/END_WHILE · FUNCTION · RETURN · DEFINE
Note: some commands are device-specific. MATCH and SAVEKEYS are Key Croc only, ATTACKMODE is Bash Bunny, and Flipper Zero adds ID, SYSRQ and ALT+numpad input.
Quick reference.
DuckyScript is the scripting language used by the Rubber Ducky and many other HID devices. It is designed to be simple and human-readable.