2026-10-23 –, Redbud A
Rubber Ducky's are pretty well known so you might hope a user won't just plug in a random parking lot flash drive, but do you think they might plug in a random keyboard that looks exactly like the keyboard they already have? Especially if they are told it is a magical keyboard that will make their computer much faster?
This talk is all about designing and building a malicious keyboard and then what you can do with it and how you might go about defending from something like this.
BadUSB vs Keystroke Injection
- Time: 2 minutes
- Compare BadUSB devices and keystroke injection devices such as the Rubber Ducky or the Bash Bunny or O.MG cable.
Keystroke Injection
- Time: 3 minutes
- Explaining how keystroke injection works on a fundamental level.
- How HID scan codes work.
- Examples of what you can do with the massive library of USB HID scan codes.
Hardware we are using
- Time: 3 minutes
- Provide some examples of hardware and the requirements for this type of tool.
- Explain exactly what hardware we are going to use for this project and why.
USB device emulation
- Time: 2 minutes
- Demonstrate how to use USB HID scan codes to pretend to be a keyboard.
Physically hiding the hardware
- Time: 5 minutes
- Explain and demonstrate how we will jam the hardware into a real Dell (or other OEM) keyboard that you will find in every office building.
- Splicing the hardware into the keyboard to allow for hiding it in software.
- Because we are splicing into the keyboard directly we can also just log every keypress in addition to injecting or modifying keystrokes.
Building the hardware to fit our requirements
- Time: 10 minutes
- Based on the physical requirements we have for space and power, as well as what types of exfiltration methods we want to use, we can pick from a wide variety of microcontrollers.
- Once we have a microcontroller picked out, we need to figure out how we are going to jam it in, and if we will provide it with any additional hardware such as an SD card reader or an additional radio of some sort.
- Once we have the requirements we need to actually build it.
- Explain the process of building it with plenty of pictures (build montage with explanations).
Hiding the hardware in software
- Time: 10 minutes
- Reading and passing on/modifying the USB HID scan codes that the keyboard is sending.
- In-depth exploration of how to view USB device conversations in Wireshark.
What we can do with this
- Time: 5 minutes
- Various options for actually attacking a company with this.
- Trying to sneak it into a stock of keyboards that will eventually get deployed.
- Walk into a business and say your with IT and that you brought a new keyboard that is magic and should help speed up their computer (make sure to put at least one unicorn on the keyboard if you use this method).
- Retrieving the data once this magic keyboard has collected it.
- Bluetooth, WiFi, and a secret third option, LoRa.
- Because we are also a keylogger we can try and log into the workstation once it's well after business hours and then try and setup a reverse shell.
Ways it could be detected / stopped
- Time: 5 minutes
- Exploring what this type of attack looks like if you are looking at the USB controller or Windows event logs.
- Exploring ways of stopping this once it is in a users hands.
I'm Isaiah, a hardware security researcher with six years of experience breaking things for fun and occasionally for work. I specialize in tearing apart white-labeled IoT devices, firmware extraction, and lock picking/bypassing. When I'm not desoldering eMMC chips or tracing wires, I'm writing Bash scripts that probably shouldn't exist and automating things in ways no one asked for. I also love cats. You can find me as codeneko or netcode in most places.