Skip to main content

O.MG Adapter — The Complete Guide

一句話定位:O.MG Adapter 把無線植入晶片藏在一顆「USB-A 轉 USB-C 轉接頭」裡——你今天可能剛剛用它幫平板充電,卻不知道它能透過 Wi-Fi 被控制。它特別的地方是:Type-C 這一端能對手機與平板執行鍵盤注入。

The O.MG family hides implants in everyday USB objects. The Adapter picks the most common travel accessory there is: the USB-A-to-USB-C dongle everyone carries to charge modern devices. Because the Type-C side is the active side, it behaves as an OTG adapter — plug it into a phone or tablet's Type-C port and you can deploy payloads to mobile devices, not just computers.

When it's not transmitting payloads, the Adapter passes normal USB 2.0 data while the implant stays undetectable. It's the discreet way to bring O.MG capability to the mobile-first world.

⚠️ Authorised testing only — ships deactivated. Test only on devices you own or with written permission. Pair with Malicious Cable Detector to understand the defensive side.


Specs at a glance

ItemSpecification
Form factorUSB-A (host) → USB-C (active/attack side) adapter
ImplantWiFi-enabled wireless HID chip (WebUI + 802.11 radio)
Payload languageDuckyScript 3.0 (Elite) / 2.0 (Basic)
MobileOTG-active Type-C side — inject into phones & tablets
ActivationRequired via O.MG Programmer — ships deactivated
Distinctive featuresSelf-destruct, geofencing, WiFi triggers, spoofed identity, data passthrough
Official docshttps://docs.hak5.org/omg-cable

Why the adapter matters — mobile attacks

ScenarioWhy the Adapter
Phone/tablet pen-testingType-C OTG injects where a USB-A device can't
Charging-station social engineeringEveryone picks up an A-to-C adapter
Mobile-first engagementModern targets are smartphones
Computer + mobile coverageSame adapter works on both

Quickstart (3-step activation)

  1. Activate: plug the Adapter into the O.MG Programmer, into a Chrome/Edge machine, open the WebFlasher (https://o.mg.lol/setup/), 3-step wizard.
  2. Connect: join the Adapter's WiFi from your browser; open its WebUI.
  3. Deploy: insert the Type-C end into the target (phone, tablet, or PC), then trigger the payload — it injects over the OTG HID link.
REM On an Android test device, open a terminal app and type
DELAY 1500
STRING echo hello from O.MG adapter
ENTER

Advanced & stealth

FeatureWhat it does
OTG active Type-CDeploys payloads to smartphones/tablets (uses the Type-C side)
Data passthroughNormal USB 2.0 data while dormant; implant invisible
Spoofable identityClone VID/PID / extended USB ID / MAC
Self-destruct / geofence / WiFi triggerStandard O.MG security controls
Encrypted C² (Elite)Remote control over encrypted tunnel from anywhere
Hardware keylogger (Elite)FullSpeed USB keylogger add-on with extra storage

Troubleshooting

SymptomCauseFix
No WebUINot activatedActivate via Programmer
Mobile doesn't receive keystrokesWrong side / OTG modeUse the Type-C side (active) on mobile; USB-A on a PC
WebFlasher can't detectBrowser / bootloaderChrome or Edge (WebSerial); unplug until prompted
Data passes but no attackDormant / payload not triggeredTrigger via WebUI or WiFi beacon