SSDP Phishing

Pose as network devices to phish Windows users



The USB Nugget can be flashed to act as a SSDP (Simple Service Discovery Protocol) device, connecting to a Wi-Fi network appearing to nearby Windows users as a network-attached drive.

This attack can be used to redirect users to phishing pages when they click on the drive. We created a demo you can find here: https://github.com/HakCat-Tech/Nugget-SSDP-Phisher/raw/main/img/Nugget-SSDP.png

You can check out the guide below to try the attack yourself: