Skip to main content

O.MG UnBlocker — The Complete Guide

一句話定位:O.MG UnBlocker 把無線植入晶片藏進一顆「安全 USB 資料阻斷器(USB 保險套)」裡——那個人人都相信最安全的裝置,其實是顆隨時能被 Wi-Fi 遙控的攻擊端點。

There is a well-known piece of defensive hardware: the USB data blocker ("USB condom"). It passes only power and blocks the data lines, so you can safely charge from an unknown port. It's the go-to recommendation for travellers and executives. The O.MG UnBlocker weaponises that trust: it looks and works exactly like a data blocker, but inside sits a dormant O.MG wireless implant.

The male end is the active attack side — when plugged into a target, it can transmit payloads. The female end passes 5V power downstream just like a real blocker, so the deception holds. Customize the label to match your target environment for maximum believability. It contains the Elite-series implant, giving industry-leading speed and future firmware capability.

⚠️ Authorised testing only — ships deactivated. This is the single most deceptive tool in the catalogue, aimed squarely at a defensive gadget people trust implicitly. Test it only on your own systems and within authorised engagements.


Specs at a glance

ItemSpecification
Form factorUSB data blocker appearance (3 colors; custom labels/logos)
ImplantElite-series O.MG wireless HID chip, dormant until triggered
PortsUSB-A male (active attack side) + USB-A female (5V power pass-through)
Payload languageDuckyScript 3.0 (Elite)
Injection speedup to 890 keys/sec
Payload slotsup to 200 (with extra storage)
Keymaps192 global keymaps built in
ActivationRequired via O.MG Programmer — ships deactivated
Distinctive featuresSelf-destruct, geofencing, WiFi trigger, spoofed ID, Port Stealthing, built-in IDE in WebUI
Official docshttps://docs.hak5.org/omg-cable

The deception, explained

ScenarioWhy the UnBlocker
Trusted-device social engineeringEveryone plugs their phone into a "safe" data blocker
Executive travelPre-placed next to a trusted charger — the last device anyone suspects
Blue-team trainingDemonstrate that even "security" hardware can be compromised
Red-team decoyCustom label/logo to match the target environment

Quickstart (3-step activation + use)

  1. Activate: insert into the O.MG Programmer, into a Chrome/Edge machine, open the WebFlasher (https://o.mg.lol/setup/), 3-step wizard.
  2. Connect: join the UnBlocker's WiFi from your browser; open its WebUI (built-in IDE included).
  3. Deploy: plug the male end into a target; trigger the DuckyScript payload from the WebUI.
REM Proof-of-concept — open notepad and type
DELAY 1000
GUI r
DELAY 500
STRING notepad
ENTER
DELAY 800
STRING Hello from an O.MG UnBlocker!
ENTER

The WebUI's built-in IDE gives live feedback (syntax highlighting, error catching) while you build payloads.


Stealth & advanced

FeatureWhat it does
Port StealthingDormant until a payload deploys — no enumeration, no logs
Spoofable identityClone VID/PID / extended USB ID / MAC
Global keymaps192 layouts to attack machines worldwide
Self-destructRemote wipe → inert; recoverable via Programmer
GeofencingTrigger/self-destruct if the device leaves scope
WiFi triggersLong-range single-beacon payload firing
Encrypted C² (Elite)Remote control from anywhere; can disable onboard WebUI
HIDX StealthLinkBidirectional tunnel Target ↔ O.MG ↔ control

Troubleshooting

SymptomCauseFix
No WebUI / inertNot activatedActivate via Programmer
"Safe" behavior onlyDormant — hasn't been triggeredTrigger via WebUI / WiFi beacon
WebFlasher can't detectBrowser / bootloaderChrome or Edge (WebSerial); connect device at prompt
Payload slowWrong DuckyScript versionUse DuckyScript 3.0 with the Elite implant on latest firmware
Accidental self-destructGeofence/rule fired out of scopeRecover with Programmer; tighten geofence scope