This page is an archive of the original crowdfunding campaign for this project. It may not be up-to-date with the latest updates and product availability. Return to the current project page.
"Within the cable housing, however, resides a tiny Bluetooth unit that waits for a wireless command to unleash its payload."
"RFID Research Group nos informa que llega USBNinja, aparentemente un cable USB...pero que en realidad es una herramienta que permite la realización de pruebas de pentesting en el ámbito de la seguridad informática."
USBNinja is an information security and penetration testing tool that looks and functions just like a regular USB cable (both power and data) until a wireless remote control triggers it to deliver your choice of attack payload to the host machine. In essence, USBNinja is the next step in the evolution of BadUSB, embedding the attack in the USB cable itself.
When plugged into a host computer, USBNinja acts just like a regular USB cable. For example, it can be used both to charge your phone and to transfer images from your phone to your computer. However, perfectly concealed within USBNinja is a very small Bluetooth device, patiently waiting. When USBNinja receives the secret command, either from a smartphone running the USBNinja app or from our custom-built Bluetooth remote control, it goes from a passive cable to a stealthy attacker by emulating a USB mouse and/or keyboard to deliver its hidden payload to the host computer.
The payload delivered by USBNinja is completely customizable. You can use the standard Arduino IDE to create your own payload and we’ll also provide plenty of examples of payloads that inject keystrokes and move and click the mouse.
USBNinja is truly a versatile tool, with applications such as practical jokes, magic tricks, secret love confessions, game assists, and information security trainings. We leave it as an exercise to the reader to come up with their own uses.
In actual use, the remote control distance is greatly affected by the environment, such as the angle of the receiving end, electromagnetic interference, obstacles that block Bluetooth, etc.
|USBNinja||Rubber Ducky||Bash Bunny||Teensy|
|Cost||$99 USD||$49 USD||$100 USD||$29 USD|
|Tools & Language||Arduino IDE, C||simple script||Bunny Script||Teensyduino IDE, C|
|Form Factor||USB cable||USB stick||USB stick||Bare board|
USBNinja - Deluxe
USBNinja - Professional
USBNinja - Pentester
USBNinja’s manufacturing will take place in four stages:
We will be fulfilling all orders ourselves, shipping via ePacket with a tracking number we’ll provide to you. If there are any rejects or delay and custom clearance issues, we will send another parcel in parallel.
If you need to change your address, please do so by visiting your Crowd Supply account page. To learn more about ordering, paying and shipping, please visit this useful page in The Crowd Supply Guide.
We are manufacturing USBNinja in-house at our production lab in Shenzhen. All PCBAs will be produced using top notch, fully automated SMT manufacturing. Quality control will be in place to test and upload a simple payload before packing USBNinjas into their product boxes. We have successfully run and delivered a previous crowdfunding campaign (Proxmark3 Rdv4.0) and we do not foresee any problems running this one. Of course, we will directly address any unforeseen problems as soon as they arise and inform backers of our progress.