Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cuddlephish — Weaponized Browser-in-the-Middle (BitM) for Penetration Testers | Kitploit
Tools/GitHubGitHub/fkasler/cuddlephish
Phishing ToolsWeb Application ExploitationPhishingPenetration TestingSocial EngineeringRed Teaming
GitHubfkasler/cuddlephish

cuddlephish

Weaponized Browser-in-the-Middle (BitM) for Penetration Testers

View Repository
673806512 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CuddlePhish

phishy

Weaponized multi-user browser-in-the-middle (BitM) for penetration testers. This attack can be used to bypass multi-factor authentication on many high-value web applications. It even works for applications that do not use session tokens, and therefore would not be exploitable using traditional token stealing attacks. This is a social engineering tool and does not exploit any technical flaws in the target service.

QuickStart

This tool is a specialized web server. It is designed to run on a Debian 11 (Bullseye) Linux server and relies on public IP information to protect the admin functionality. Don't expect to be able to test locally without jumping through some serious hoops.

Warning: Chromium is not supported on ARM. While it is technically possible to force the use of an ARM chromium binary, you will lose all the additional features/protections of puppeteer-extra.

This example setup utilizes Caddy to handle TLS, SNI, and add a couple of custom headers like 'X-Real-IP' to each request. You don't have to use Caddy with Cuddlephish, as the same reverse proxy can be set up using Nginx, Apache, etc. I just like Caddy because it is easy to install with Docker, and has plugins to manage Letsencrypt certs for most domain registrars. The example Caddyfile shows how you would set it up for Gandi. Check the docs for your registrar.

Install Docker, Node, XVFB, and some other dependencies:

git clone https://github.com/fkasler/cuddlephish
cd cuddlephish
sudo bash install_deps.sh

You can then use Docker to build Caddy with a wildcard cert plugin for your registrar. The example is for Gandi. Check the docs here and the list of dns provider modules here. You can mod the Dockerfile for your registrar before building:

sudo docker build -t caddy .

Now mod the Caddyfile to swap your domain and Gandi (or other registrar) API key, and start Caddy. I recommend starting this in a screen or tmux window so that you can run the Node server in another window in a moment:

sudo docker run -p 80:80 -p 443:443 -p 2019:2019 -v $PWD/Caddyfile:/etc/caddy/Caddyfile --network=host caddy:latest

With Caddy fielding traffic for us on 80 and 443, we can finally run the tool!

Install the Node dependencies:

npm install

A few config tweaks: CRITICAL STEP: Make sure to mod the example config.json to add your approved public IP(s) for admin access. This whitelist of IPs is what dictates access to the "/admin" web interface. You should also change the default socket key to something more secure.

The tool is not set up to target any logins by default so you will need to add some. There is an 'add_target.js' script to make this step easy. Just run the script and paste in the URL of the login portal you would like to target when prompted:

node add_target.js

This will grab the service name, tab title, and favicon for you and add an entry to 'targets.json'. You can run this script multiple times and it will append your new targets. The script will name each service based on the domain, without the top level. So, for 'https://www.example.com/login.php' the service would just be 'example' when specifying your target when you...

Run it!

node index.js example

After a few seconds, you should see a message in the console when your first automated Chrome instance checks in over websockets. Now visitors to your phishing site should see what appears to be the target login page but is actually a video feed of your automated browser instance. They can also interact with your browser instance and log in for you.

If you properly configured your admin IP(s) in the config.json, you should be able to view a special '/admin' web interface to track users, view key logs, takeover control of logged in browser instances, steal cookies, and delete unwanted browser instances.

Note: You will not see anything in the admin page until you have some victims. Once you have a victim, their browser instance should pop up on the admin UI.

Troubleshooting ("I just see a blank page")

I have had several people open issues about a "Blank White Page", which is more of a symptom of many possible issues, and not an issue in itself. Please do not open issues under vague symptom names. Instead, if you have a blank page on the user side, try first looking into the following:

  • Check that the tab title of the target service does not have any special characters in it. We use "--auto-select-desktop-capture-source" to tell our automated browser what tab to stream. This option fails for titles with special characters in them. However, you don't need the full tab title to mach, and just need enough of a substring for a unique match.
  • Along the same line, if your target service sends a 302 or similar redirect to your automated browser, and the tab title changes before we start the WebRTC broadcast to a vicitim, then "--auto-select-desktop-capture-source" will fail. You can look at how add_target.js grabs this information, and replicate it on the index.js along with a console.log() statement to see if the title is has changed before negotiating WebRTC.
  • Check that the cuddlephish HTML is loading, and that there aren't any obvious JavaScript errors in the developer console on the front-end. The example Caddy config has some basic blocks on user agent strings like curl. At a minimum, you should see that the tab title and favicon are being spoofed.
  • Ensure that you can interact with the example STUN service and port (stun.l.google.com:19302) from your server.
  • Ensure that the network you are working from even allows STUN. STUN only works with "full-cone NAT", "(Address)-restricted-cone NAT", and "Port-restricted cone NAT". It DOES NOT work with "Symmetric NAT".
  • Ensure you can interact with the example STUN service and port (stun.l.google.com:19302) from your test victim browser. Try using https://icetest.info/.
  • If your network cannot reach the example STUN server, then change it to one you can reach. If your network does not allow STUN, then there is an example config for a TURN server in the cuddlephish and broadcast HTML pages. You will have to set up or pay for your own TURN server. NOTE: A TURN server has the best chance of connecting phishing vicitims to with your browser instances.

At a high level, if you just see a blank page on the front-end, then it means there is some breakdown occuring in the chain of data flow from "Start WebRTC" > "Select Tab to Broadcast" > "Negotiate ICE with Vicitim's Browser" > "Stream Video". The above troubleshooting steps are intended to help you follow the data through this process. When working properly, you should expect to see a log stream on the server similar to the following:

troubleshoot

I hope this helps with any issues, and as always, sufficient information to consistently replicate an issue is a prerequisite for submitting issues for further investigation.

Admin Features

Send Payload:

Manually trigger a payload to download to the victim's system via JavaScript. Each target starts off with 'payload.txt' as a test payload. Just swap the file location in targets.json to send a custom payload.

Boot User:

Sends a window.location change to the victim to send them to the real login portal. It will seem like they are just being forced to re-authenticate and prevent them from watching you take the controls. If you mod the code, you could do some other fancy things with this general technique ;)

Download Tool