GHOST-5 — Dual-Band Pentesting Development Kit
BW16 Specter | RTL8720DN | 2.4GHz + 5GHz Dual-Band WiFi & BLE 5.0
Product Overview
GHOST-5 is a dual-band Wi-Fi + BLE 5.0 penetration testing development board based on the Realtek RTL8720DN (BW16) chipset. Designed for wireless security research, firmware development, and IoT experimentation, it combines a high-performance ARM V8 (Cortex-M4F compatible) MCU with a low-power ARM V8M (Cortex-M0 compatible) MCU in a dual-core architecture. By integrating 2.4GHz and 5GHz dual-band Wi-Fi alongside Bluetooth 5.0 LE, GHOST-5 delivers a complete portable wireless security testing platform in the palm of your hand.
Unlike common 2.4GHz-only ESP32-based solutions, GHOST-5 natively supports the 5GHz band, enabling you to observe and analyze a much wider spectrum of wireless environments. Whether you are conducting enterprise-grade 5GHz Wi-Fi penetration tests, capturing WPA/WPA2 handshakes, collecting PMKIDs, or performing BLE device reconnaissance and attacks, GHOST-5 handles it all on a single board.
Pre-flashed with the full GHOST-5 firmware ecosystem, it features a 1.8-inch TFT color display and a five-way navigation keypad, allowing it to run independently out of the box—no computer, no external host required. It also supports firmware updates and extended development via USB-C.
Core Technical Features
🔥 Dual-Band Wi-Fi Reconnaissance
Powered by the RTL8720DN chipset, GHOST-5 supports 2.4GHz and 5GHz dual-band 802.11 a/b/g/n wireless connectivity. The 5GHz capability allows it to detect and analyze network environments that are invisible to typical 2.4GHz-only tools.
-
Dual-Band AP Scanning – Real-time scanning of all access points across both 2.4GHz and 5GHz bands, displaying signal strength, encryption type, channel information, and WPA3/PMF (802.11w) detection.
-
Channel Congestion Analysis – Visualizes channel occupancy across both bands and intelligently highlights the least congested channels.
-
Wi-Fi Station Recon – Enumerate associated clients on target networks, enabling targeted deauthentication and on-demand handshake capture.
📡 Advanced Wireless Attack Suite
-
Deauth Attacks – Supports deauthentication attacks on both 2.4GHz and 5GHz bands, with automatic detection of 802.11w / WPA3 protected APs to warn (rather than silently fail).
-
PMKID Capture (Beta) – Pull PMKIDs directly via AUTHPROBE association without waiting for a client to connect. Export in .22000 + .json formats.
-
5GHz Handshake Capture – Sniff WPA/WPA2 4-way handshakes, exporting to standard PCAP format ready for Hashcat (mode 22000) or aircrack-ng.
-
Multi-SSID Beacon Spam – Transmit custom, random, or prank SSID beacons for coverage mapping and captive portal stress-testing.
🎯 BLE 5.0 Security Toolkit
-
BLE Device Scanner – Multi-round de-duplicated scanning identifying device manufacturers, Find My / AirTag trackers, nearby Flipper Zero devices, and AP vendor OUIs.
-
BLE Attack Modules – Sour Apple (triggers pop-ups on Apple devices), Android Spam (fast-pair noise on Samsung/Android), Swift Pair (triggers Windows pop-ups), and Kitchen Sink (random rotation of all three).
-
BLE Spoofer – Emulate mainstream Bluetooth devices such as AirPods, AirPods Pro, and Beats for proximity-based device discovery testing.
-
BLE Ducky – Execute Ducky Script payloads via BLE HID keyboard emulation (includes 5 presets: Hello World, Device Info, Open Browser, Run CMD, Mute Toggle).
🛸 Drone Detector (Open Drone ID)
Passively monitor Wi-Fi channels and decode ASTM Remote ID (Open Drone ID) protocol packets in real time. Identify:
-
Basic drone IDs (Serial Number / CAA Registration / UUID)
-
Real-time location (Latitude, Longitude, Altitude, Speed, Direction)
-
Operator ID and position
-
Flight status (Ground / Airborne / Emergency)
-
Aircraft type (Multirotor / Fixed-wing / Helicopter / etc.)
🕸️ Captive Portal & Evil Twin
-
Captive Portal – Creates a fake “Free Wi-Fi” hotspot to capture credentials from connecting users.
-
Evil Twin AP – Clones legitimate access points with custom HTML login pages or templates loaded from SD card.
-
Credential Storage – All captured passwords are stored and viewable in real-time.
🎨 Full-Color Theme System
Built-in 11 Cyberpunk-style themes:
-
GHOST-5 (Classic Cyan/Magenta)
-
Rustic Yellow, Aqua Green, Lemon Green
-
Flipper Orange, Neon Magenta
-
Kali Dragon, Matrix Green
-
Cyberpunk Neon, Vaporwave, Hologram
Theme switching takes effect instantly and persists to flash memory.
Hardware Specifications
| Item | Specification |
|---|---|
| Main Chip | Realtek RTL8720DN (BW16) |
| Core Architecture | ARM V8 (Cortex-M4F compatible) + ARM V8M (Cortex-M0 compatible) Dual-Core |
| Wi-Fi | Dual-Band 2.4GHz / 5GHz, 802.11 a/b/g/n (1×1) |
| Bluetooth | BLE 5.0, High-power mode 7dBm |
| Display | 1.8-inch TFT Color Display (128×160) |
| Memory | 2MB Flash |
| Interfaces | UART / GPIO / ADC / PWM / I²C / SPI / SWD |
| Power Supply | USB-C (5V) or 3.0V–3.6V External |
| Antenna | Onboard PCB Antenna / IPEX Connector |
| Navigation | 5-Way Buttons (UP / OK / DOWN / BACK) |
| Dimensions | Standard Developer Board Size |
Software Feature Matrix
| Module | Description |
|---|---|
| Wi-Fi AP Scanner | Dual-band AP list with signal, encryption, channel, WPA3/PMF detection |
| Wi-Fi Channel Analyzer | 2.4GHz occupancy bar graph + 5GHz AP list |
| Wi-Fi Packet Monitor | Real-time scrolling oscilloscope-style traffic graph |
| Deauther | Dual-band deauth attacks with automatic PMF protection detection |
| Beacon Spam | Multi-SSID beacon broadcasting (40+ prank SSIDs preloaded) |
| Captive Portal | Rogue hotspot creation + credential harvesting |
| Evil Twin | Legitimate AP cloning + custom login pages |
| BLE Scanner | BLE device discovery with detailed information view |
| BLE Attacks | Sour Apple / Android Spam / Swift Pair / Kitchen Sink |
| BLE Spoofer | AirPods / Beats / Apple TV device simulation |
| BLE Ducky | BLE keyboard script injection (5 presets) |
| Drone Detector | Open Drone ID real-time decoding and localization |
| AirTag Detector | Apple FindMy / Samsung SmartTag / Tile tracker identification |
| Skimmer Detector | Suspicious Bluetooth serial module identification (HC-05/HC-06/RNBT) |
| Flipper Detector | Nearby Flipper Zero device identification |
| Theme System | 11 Cyberpunk themes with persistent flash storage |
| Web Console | Access device dashboard via AP for status viewing, theme switching, and triggering Wi-Fi scans |
Technical Specifications
| Parameter | Details |
|---|---|
| Wi-Fi Bands | 2.4GHz (Channels 1–14) / 5GHz (36–165) |
| Wi-Fi Standards | 802.11 a/b/g/n |
| Bluetooth Standard | BLE 5.0 |
| Modulation | 64-QAM / BPSK / CCK |
| Operating Voltage | 3.0V – 3.6V (Typical 3.3V) |
| Operating Current | >500mA |
| Display Driver | ST7735 |
| Firmware Update | USB-C Serial Flashing / Browser Recovery |
| Development Environment | Arduino IDE / Ameba SDK |
What’s in the Box
-
1 × GHOST-5 Development Board (BW16)
-
1 × USB-C Data Cable
Important Notes & Legal Disclaimer
-
This is a standalone device – all features are operational out-of-the-box without requiring a connection to Flipper Zero or any external host.
-
GHOST-5 comes pre-flashed with the complete firmware; plug and play ready.
-
Firmware can be upgraded via USB-C.
-
Intended for authorized security testing, educational learning, and legitimate research purposes only.
-
Unauthorized interception or disruption of wireless networks is illegal in most jurisdictions.
-
End users are solely responsible for complying with all applicable laws and regulations – including FCC Part 15 (USA), CE / RED (EU), and local equivalents.
-
This product is provided AS-IS without any warranty.
Why Choose GHOST-5?
Most Wi-Fi penetration testing tools on the market are built around the ESP32 platform, which supports only the 2.4GHz single band—meaning they cannot see or test more than half of the wireless spectrum. GHOST-5, powered by the RTL8720DN chipset, natively supports 2.4GHz AND 5GHz dual bands, giving you complete coverage of modern Wi-Fi networks.
Combined with the 1.8-inch color display, tactile five-way navigation, and a comprehensive BLE 5.0 toolchain, GHOST-5 consolidates all essential wireless security testing capabilities into a portable, handheld device—no computer, no extra modules, and no complex command-line operations required.
GHOST-5: Dual-Band Wireless Security, Right in Your Hand.











Reviews
There are no reviews yet.