O.MG Unblocker (Trojan Horse Data Blocker Hacking Hardware)
- Biohazard

- Jul 23
- 6 min read

O.MG Unblocker (Full Elite-Series Implant)
This is one of the most brilliantly deceptive tools in the O.MG lineup. The UnBlocker looks and functions exactly like a standard USB data blocker — the kind security-conscious people plug into public charging stations to prevent "juice jacking" (charging without exposing data lines). It passes 5V power to any downstream charging cable. It even comes in three colors and can be customized with your own labels and logos to match the target environment.
Inside that innocent data-blocker shell sits a full O.MG Elite-series implant: WiFi radio, web server, DuckyScript engine, hardware keylogger, encrypted C2, HIDX covert channel, self-destruct, geo-fencing, and WiFi triggers. The target thinks they're being security-conscious. They just plugged an implant into their own machine.
Price: $149.99
Hardware Specifications
Component | Detail |
Implant | O.MG Elite series (Gen 3) |
CPU | O.MG Elite microcontroller |
WiFi | 802.11 b/g/n, 2.4 GHz, internal antenna |
Interface | USB Type-A male (active end — delivers payloads) to USB Type-A female (pass-through power only — 5V to downstream device) |
Data passthrough | ❌ None — this is a data blocker. Only power passes through to the female port. Data lines are blocked, exactly like a legitimate data blocker. |
Keystroke Injection | ✅ 890 keys/sec (industry-leading) |
Payload Slots | Up to 300 (Elite) |
Hardware Keylogger | ✅ ~650,000 keystrokes storage |
Keymaps | 192 built-in |
Stealth | VID/PID spoofing, extended USB identifier spoofing, MAC address spoofing, Port Stealthing (dormant until payload deploys) |
Network C2 | Encrypted, compatible with any Python-running server |
Self-Destruct | ✅ Fully inert (recoverable with O.MG Programmer) |
Geo-Fencing | ✅ Trigger actions or self-destruct based on location |
WiFi Triggers | ✅ Trigger payloads via beacon at long range |
HIDX StealthLink | ✅ Bidirectional tunnel: Target Host → O.MG → Control Machine |
Activation | Ships deactivated — requires O.MG Programmer + 3-step WebUI activation |
Colors | 3 options |
Customization | Custom labels/logos to match target environment |
The Social Engineering Genius
The attack vector is inverted. With most implants (O.MG Cable, Rubber Ducky, Bash Bunny), the operator has to physically swap hardware — replace a cable, plug in a device. With the UnBlocker, the target does the work for you.
The scenario: You leave the UnBlocker in a target area — a shared workspace, a hotel business center, a conference charging station, an airport lounge. It looks like a thoughtful data blocker someone left for security. A target picks it up, thinks "smart," and plugs it between their laptop and a charging cable. They feel protected from juice jacking. You now have a wireless implant on their machine with 890 keys/sec DuckyScript, encrypted C2, and a hardware keylogger.
It's a data blocker. It's functioning exactly as advertised — blocking data to the downstream port. The target never suspects the male end they plugged into their own machine is the active attack surface.
Full O.MG Elite Feature Set
The UnBlocker carries the complete Elite-series implant feature set. Every capability of the O.MG Cable Elite applies here:
Feature | Detail |
Keystroke Injection | DuckyScript payloads, 890 keys/sec, instant deploy — no compiling, just click Run |
Hardware Keylogger | Passively captures ~650,000 keystrokes through the USB host |
WebUI IDE | Full control via browser (desktop or mobile), live syntax checking |
192 Keymaps | Target any language/keyboard layout |
VID/PID Spoofing | Appear as any USB device — Apple adapter, Dell dongle, generic hub |
MAC Address Spoofing | WiFi MAC customization |
Port Stealthing | Implant stays dormant. No USB device enumerated. No logs. No detections. Only activates when payload deploys. |
Encrypted Network C2 | Connect to any Python C2 server. Disable onboard WebUI for total stealth on untrusted networks. |
HIDX StealthLink | Bidirectional covert channel over HID reports. Data exfiltration from target to O.MG to control machine, even air-gapped. |
Self-Destruct | Fully inert — firmware wiped. Recoverable only with O.MG Programmer. |
Geo-Fencing | Trigger payloads or self-destruct based on GPS-defined boundaries. Device leaves scope? It bricks itself. |
WiFi Triggers | Send a beacon from long range. UnBlocker detects it, launches predefined payload. No direct WiFi connection needed. |
Mobile Device Payloads | USB-C active end models can deliver to Android/iOS devices (with adapter) |
Comparison: UnBlocker vs. O.MG Cable
Aspect | O.MG Cable | O.MG UnBlocker |
Physical form | USB cable (various connectors) | USB data blocker dongle |
Appearance | Identical to normal cable | Identical to security data blocker |
Data passthrough | ✅ USB 2.0 480 Mbps | ❌ Data blocked (by design — it IS a data blocker) |
Charging passthrough | ✅ 5V | ✅ 5V |
Active end | USB-A (or configured) | USB-A male |
Downstream | Connects to device | Passes power only to charging cable |
Social engineering angle | Swap a cable | Target voluntarily plugs it in themselves |
Deployment | Operator must physically swap | Leave it somewhere, target picks it up |
Stealth | Extreme — looks like a cable | Extreme — looks like a security device the target wants to use |
Implant | O.MG Elite | O.MG Elite (identical internals) |
Price | Varies by model | $149.99 |
Operational Scenarios
1. The Airport Lounge Drop
You're on a physical engagement targeting traveling executives. Leave an UnBlocker at a charging station in the business lounge. Executive sits down, sees the data blocker, thinks "good, I don't want to get hacked," plugs their laptop into the UnBlocker, then their charging cable into the UnBlocker. Laptop charges. Executive sends emails for 45 minutes. Every keystroke is logged to the UnBlocker's internal storage. Their password, their confidential emails, their VPN credentials. You retrieve the UnBlocker later or stream keystrokes live via C2 over the lounge WiFi.
2. The Security-Conscious Employee
Target organization promotes "USB security awareness." Employees use data blockers. You replace one of their data blockers with an identical-looking UnBlocker. Employee plugs it in every day thinking they're doing the right thing. You have persistent access for weeks.
3. The Conference Swag Table
Custom-label the UnBlocker with the target company's logo. Place it on a swag table at an industry conference. It looks like branded security merchandise. Target employees take them, plug them in. You have simultaneous implants across the organization.
4. The "Helpful IT" Plant
During a physical penetration test, you're inside the building. You place UnBlockers at hot-desking stations and meeting room charging points. Remote workers and visitors plug in. Multiple implants across the network within hours.
5. Combined with WiFi Trigger
You place the UnBlocker on a target's desk. You're outside the building. You send a WiFi beacon from a directional antenna. The UnBlocker detects the beacon, deploys its payload — opens a reverse shell, dumps credentials, exfiltrates files — then self-destructs. The target returns to their desk and finds a data blocker that no longer works. They throw it away. No evidence.
6. C2 Remote Monitoring
UnBlocker connects to the target's office WiFi as a client, phones home to your Cloud C2 server. You monitor keystrokes in real time from anywhere. Deploy payloads on demand. Inject keystrokes live. Change configuration remotely. All through a data blocker sitting innocently on the target's desk.
Activation & Setup
Ships deactivated by regulation. Activation requires the O.MG Programmer (included with O.MG Cable purchases, or sold separately):
Plug O.MG Programmer into PC
Plug UnBlocker into Programmer
Browse to the WebFlasher utility (WebSerial-compatible browser: Chrome/Edge)
Follow the 3-step activation process
UnBlocker now broadcasts its own WiFi AP
Connect to it, browse to WebUI, configure payloads
Deploy
Alternatively, use the Python flasher for activation.
Key Limitations
No data passthrough — by design. If the target expects to sync data through the UnBlocker (e.g., plug their phone into their laptop through it), it won't work. This could raise suspicion if the target tries to use it for data.
WiFi is 2.4 GHz only — same as all O.MG devices.
Passive-only downstream — the female port passes power only. You can't chain a second implant or USB device through it.
Physical size — slightly larger than a standard data blocker due to the implant. Noticeable if directly compared side-by-side, but indistinguishable in isolation.
Requires O.MG Programmer — can't activate without it. Make sure you have one in your kit.
One active end — payloads deploy through the male USB-A connector. The female port is power-only. Only the device plugged into the male end is the target.
Quick Comparison: O.MG Ecosystem
Tool | Best For | Covertness | Attack Vector |
O.MG Cable | Cable swap, keyboard logging, mobile payloads | Extreme — identical to cable | USB host (cable swap) |
O.MG UnBlocker | Target self-deployment, shared charging stations | Extreme — security device cover | USB host (target plugs in voluntarily) |
O.MG Adapter | USB-C to USB-A conversion + implant | High — looks like adapter | USB host (adapter swap) |
O.MG Plug | Wall charger implant | Extreme — looks like charger | USB host + AC outlet |







Comments