Rimausb security
MYPI2025000620A0Pending Publication Date: 2026-07-23UNIVERSITI MALAYSIA PERLIS UNIMAP
0 Cites 0 Cited by
Patent Information
- Authority / Receiving Office
- MY · MY
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2026-07-23
Abstract
The invention presented herein addresses the growing threat of USB-based credential theft, specifically focusing on BadUSB attacks and the exfiltration of sensitive data such as WiFi passwords. Using a custom coding script in DuckyScript, this system exploits vulnerabilities in USB devices to simulate keystrokes and execute commands on a victim’s machine. The script retrieves stored WiFi credentials and sends the exfiltrated data to a secure Discord webhook, enabling attackers to access the stolen information remotely. The system also incorporates mitigation techniques to evade detection, ensuring that the attack remains undetected in environments where security measures might be in place. By leveraging hardware components such as the Arduino Pro Micro microcontroller (2) and the ESP8266 Wi-Fl module (3), the system enables wireless communication for data exfiltration and offers a scalable solution for penetration testing of USB-based security vulnerabilities. This invention provides an advanced approach to detecting, mitigating, and simulating BadUSB attacks, enhancing overall security resilience against USB-based credential theft and data breaches. (FIGURE 1)
Need to check novelty before this filing date? Find Prior Art