
Useful links:
Key Croc
The Key Croc plugs between a USB keyboard and the target computer, capturing keystrokes transparently while passing all input through to the system without raising suspicion. It automatically clones the hardware identifiers (VID/PID) of the connected keyboard, presenting itself to the system as the original keyboard. Its most powerful feature is the pattern matching system: DuckyScript payloads that execute automatically when the user types a defined keyword sequence, with no manual intervention from the operator. In attack mode it simultaneously emulates HID (keyboard), Ethernet, USB storage and serial device, enabling keystroke injection, network access bypassing perimeter firewalls, data exfiltration and serial access, all from a single implant. Based on Debian Linux with a quad-core ARM CPU at 1.2 GHz and 8 GB SSD, it includes pre-installed pentesting tools (nmap, Responder, Impacket, Metasploit) accessible via SSH or serial console. Built-in 2.4 GHz WiFi for remote management via Hak5 Cloud C2: real-time keystroke streaming, remote keystroke injection, loot exfiltration and root shell from a browser. Zero-configuration setup: a hidden button turns the device into a flash drive to edit payloads and config directly as text files. Dimensions: 74 x 27 x 14 mm.
Main features:
- Transparent keylogger passthrough to the target system
- Automatic VID/PID cloning of the connected keyboard
- Pattern matching: payloads triggered on defined keyword detection
- Simultaneous multi-vector emulation: HID, Ethernet, USB storage, serial
- Embedded Debian Linux with root shell (SSH and serial console)
- Quad-core ARM CPU 1.2 GHz, 8 GB SSD
- Pre-installed tools: nmap, Responder, Impacket, Metasploit
- Built-in 2.4 GHz WiFi
- Remote management via Cloud C2: keystroke streaming, remote injection, root shell
- DuckyScript for payload development
- Zero-configuration setup: arming mode via hidden button
- 74 x 27 x 14 mm, USB 2.0, 5W