Hydra-ESP
A wireless security research firmware for the ESP32. Runs its own management access point and web UI, with Wi-Fi and Bluetooth attack modules for testing networks and devices you own, or are explicitly authorized to test.
2What changed since v1.0
v1.0 (the video with 62K+ views) was mostly deauth + a plain web UI. Since then:
- Redesigned web interface — same
192.168.4.1flow, new layout and theme. - Deauth is no longer one fixed method — four selectable modes, including a BSSID-clone mode that gets around 802.11w/MFP.
- Evil Twin now actually verifies a captured password against the real AP before reporting it, instead of logging whatever gets typed.
- BLE spam expanded to 25 selectable device-pairing signatures across Apple, Samsung, and Google.
- BT payload module added — Bluetooth HID keyboard spoofing with five built-in payloads.
- Deauth attack detector added — the one purely defensive module in the firmware.
- Optional SSD1306 OLED support for status without the web UI.
3Hardware
| Required | ESP32 DevKit V1, or any board on the same Xtensa LX6 dual-core chip — ESP32-WROOM-32 and ESP32-WROVER modules are expected to work. |
|---|---|
| Not supported | ESP32-S2, S3, C3, and other variants — different radio hardware, won't run this firmware. |
| Optional | SSD1306 OLED, 128×64, I2C. Auto-detected on boot; shows attack timers, status, menu, and captured Evil Twin passwords. If it's not connected, init is skipped quietly and nothing else is affected. |
4How it works
On boot the ESP32 starts its own management access point. Connect a phone or laptop to it and open http://192.168.4.1 — the UI is served straight off the device's flash (SPIFFS), no internet connection needed.
Some modules (Deauth, Evil Twin, Super Clone) need the radio to themselves, so the management AP goes down while they run — you'll lose the web UI connection for the duration. Set a timeout and it comes back on its own; leave it unset and you'll need to power cycle the board to stop the attack and get access back.
5Wi-Fi modules
5.1Deauthentication
Sends forged 802.11 deauth frames to drop clients off a target AP. Up to 16 targets at once.
- Normal Deauth — plain deauth frames, the standard method.
- Combined Deauth — deauth + disassociation frames together.
- Multi-Clone Deauth — runs across several cloned identities instead of one.
- BSSID Clone (Aggressive) — clones SSID + BSSID onto the ESP32 on the same channel, so the real AP and the clone look identical. Drops clients through address collision rather than a raw deauth frame, which is why it still works against 802.11w/MFP-hardened devices.
Default timeout 2 minutes, adjustable 1–255. Disable the timeout and it runs until you power cycle the device.
5.2WPA Handshake Capture
Forces a reconnect, records the resulting WPA2 4-way handshake as .pcap and .hccapx for offline auditing with Hashcat or Aircrack-ng. A connected client on the target network is required.
- Normal Deauth / BSSID Clone (Aggressive) — force a reconnect the same way the Deauth module does.
- Silent Capture — no forced disconnect, just waits for a client to reconnect naturally.
5.3Clientless PMKID Capture no client needed
Pulls the PMKID from the first EAPOL-Key frame during association — only the AP needs to be in range, no connected client required. Compatible with Hashcat hash mode 22000. Most modern WPA2 APs leak this; some don't include it at all.
5.4Beacon Spam
Floods the area with 1–100 fake 802.11 beacon frames, cluttering the Wi-Fi scan list on every nearby device. Default timeout 5 minutes.
- Common Names — everyday-looking SSIDs, blends into normal noise.
- Random Strings — obviously-fake gibberish SSIDs.
- Rick Roll Mode — exactly what it sounds like.
- Security Names — SSIDs styled to look like security/surveillance gear.
5.5Ghost Mode probe harvesting
Listens for the SSIDs nearby devices are probing for from their own saved-network lists, then advertises those exact names back, so devices try to auto-connect to the ESP32 instead of their real saved network. No configurable mode — just run it. Default timeout 5 minutes.
5.6Evil Twin verifies password
Labeled "Devil Twin" in the UI. Stands up an open clone of the target AP (same SSID, no password) and deauths the real one at the same time to push clients onto the clone. Runs its own DNS server so every request from a connected client is redirected to a captive portal — a fake update-style page asking for the network password.
A submitted password isn't just logged blind: the firmware attempts a real connection to the target AP with it to confirm it's correct. Wrong guess → logged as a failed attempt, victim is sent back to the portal. Correct guess → captured, verified, and shown in the web UI.
Default timeout 5 minutes. Web UI is unreachable while this runs.
5.7Super Clone
The SSID-cloning module — stands up several APs sharing (near-)identical SSIDs by padding the real name with trailing spaces, so a scan list shows what looks like duplicate copies of the same network. One mode: Open Multiple Clones. Default timeout 5 minutes.
6Bluetooth / BLE modules
6.1BLE Spam
Broadcasts BLE advertisement packets mimicking Apple, Samsung, and Google proximity-pairing signals — nearby iPhones, iPads, and Android devices show pairing popups as if a real accessory were in range. Default timeout 15 minutes, MAC address rotates every run.
| Apple Audio | 8 modes — AirPods, AirPods Pro, AirPods Max, Beats-style pairing popups |
|---|---|
| Apple Setup | 5 modes — Apple TV, HomePod, Vision Pro-style setup prompts |
| Samsung | 6 modes — Galaxy Buds variants 1–5, plus a random mode |
| 5 modes — Fast Pair variants 1–4, plus a random mode | |
| Mixed Random | 1 mode — picks across all of the above at random |
6.2BT Payload
Advertises the ESP32 as a Bluetooth HID keyboard under a random name (HydraBT-####) with a freshly randomized MAC each run. Once a host pairs with it, it types out one of five built-in payloads. Mostly aimed at Windows hosts — pair from Android with an app like nRF Connect.
- Write to Notepad — opens Notepad, types a short message.
- Play Rick Roll (YouTube) — opens the default browser to a YouTube link.
- Set Warning Wallpaper — downloads an image, sets it as desktop wallpaper. May need a restart to fully apply; the host needs to be online to fetch the image.
- Grab Wi-Fi Passwords — reads saved Wi-Fi profiles off the host machine and posts them back over HTTP to the ESP32's own log endpoint, or a custom remote URL / RequestBin if one's set in the UI.
- Hydra God Mode — runs the bundled prank script (wallpaper swap + sound).
main/bt/bt_payload_attack.cpp, wired into a switch statement in execute_current_payload(). To add one: write a do_payload_N function that presses/releases keys through s_keyboard, add a matching case N:, and add a button for it in data/index.html / data/app.js following the existing five. Standalone scripts a payload downloads and runs (like the two .ps1 files already in the repo) belong in /payloads at the repo root — that's the place to drop new script files. PRs for new payloads are welcome, see CONTRIBUTING.md.
7Deauth attack detector
The one defensive module in the firmware. Puts the radio into promiscuous 802.11 monitor mode and watches raw management frames, flagging any source BSSID that sends more than 10 deauth frames within a second — the standard signature of an active deauth attack — and separately flagging broadcast deauth frames from the reserved source 00:00:00:00:00:00. Results show up live in a log table in the web UI. It can't run alongside an attack module, since both need sole use of the one radio the board has.
8Web interface
Connect to the device's AP and open http://192.168.4.1.
| Scan | Nearby SSIDs, BSSIDs, and signal strength — tap a row to select it as the target |
|---|---|
| Attack | Configure and launch any module above, with live status, timer, and results |
| Detector | Start/stop the deauth monitor and view the alert log |
| Settings | Change the management AP's SSID and password — device reboots on save |
| About | Firmware version, credits, legal notice |
| Default SSID | hydra |
|---|---|
| Default password | notforfun |
| Web UI | 192.168.4.1 |
9Build & install
Needs ESP-IDF set up, targeting the standard ESP32 chip.
git clone https://github.com/SameerAlSahab/Hydra-ESP.git cd Hydra-ESP idf.py set-target esp32 idf.py build idf.py -p /dev/ttyUSB0 flash monitor
Prefer flashing a release build directly instead? Grab the binaries from the Releases page and flash with esptool.py or the Espressif flash tool at the standard offsets (bootloader → 0x1000, partition table → 0x8000, app → 0x10000, SPIFFS storage → 0x190000).
Once it's flashed: join the hydra network, open 192.168.4.1, and change the default SSID/password from Settings before doing anything else.
10Citation
A companion paper walks through the 802.11/BLE background behind everything on this page — the protocol-level mechanism each module exploits, and the countermeasures that actually address the root cause (802.11w, WPA3-SAE, rogue-AP detection, tighter BT pairing policy). If you're citing the firmware or the paper, use the repo's CITATION.cff — GitHub's "Cite this repository" button reads it automatically — or the BibTeX below.
@article{alsahab2026hydraesp,
author = {Al Sahab, Sameer},
title = {Low-Cost IEEE 802.11 and Bluetooth Attack Surfaces on
Commodity Microcontrollers: A Case Study of the ESP32 Platform},
year = {2026},
url = {https://github.com/SameerAlSahab/Hydra-ESP/blob/main/paper/hydra_esp_paper.pdf},
note = {Firmware and paper available in this repository.}
}
11Legal & ethics
12Credits
| Lead developer | Sameer Al Sahab |
|---|---|
| Original codebase | risinek/esp32-wifi-penetration-tool |
| Inspiration | SpacehuhnTech/esp8266_deauther |
| BLE spam code | justcallmekoko and ckcr4lyf (EvilAppleJuice-ESP32) |