Karma Attack
Automatically respond to device probes with fake networks
On this page
Create fake Wi-Fi networks based on SSIDs that nearby devices are searching for. When a device searches for a network, Karma broadcasts it back; when the device connects, a captive portal starts automatically to capture credentials. In automatic mode Karma learns SSIDs from probe requests, while custom mode broadcasts SSIDs you specify. You need a flashed, powered device with a wireless antenna; an SD card is optional for Evil Portal integration.
Note: Only test on networks you own or have permission to test. See Legal and ethical rules.
ClientAttacker
Probe Request (broadcast)The client names an SSID it is looking for
Probe Response (spoofed SSID)GhostESP answers as that network
association + DHCPThe client joins the fake open network
captive portalOptional portal page served on connect
Karma answers the networks a device is already asking for.
Starting Karma
On-device UI
- Open Menu → Wi-Fi → Attacks → Karma Attack. The device will begin learning SSIDs from probe requests.
- To use specific SSIDs instead, choose Karma Attack (Custom SSIDs). Enter the SSIDs you want to broadcast (separated by commas), up to 32.
- To serve a custom captive portal on the fake networks, choose Karma Attack (Custom Portal).
- The device will start broadcasting fake networks. Leave it running to catch devices.
- To stop, go back to the menu or select Stop Karma Attack.
CLI
- Run
karma startto begin automatic SSID learning. The device will cache SSIDs from probe requests. - Or run
karma start SSID1 SSID2 SSID3to use specific SSIDs (up to 32). Example:karma start FreeWiFi Starbucks McDonald's - Run
karma stopwhen you’re done.
The learned-SSID cache holds at most 32 SSIDs.
Troubleshooting
- Fake networks not appearing: Try restarting with
karma stopthenkarma start. - No devices connecting: Ensure devices are actually searching for networks. Try moving closer to the GhostESP device.
