Description
▌PRODUCT DESCRIPTION
>> THE SWISS ARMY KNIFE BOOTED INTO ATTACK MODE. <<
Your Flipper is cute. It’s got a dolphin. It does party tricks at the office. But when you need a real tool that covers WiFi, Bluetooth, sub-GHz, 2.4 GHz, infrared, NFC, GPS, FM radio, and BadUSB from a single pocket-sized board running open-source firmware you can actually modify, the dolphin starts to look like a toy.
The Bruce PCB V2 (Smoochiee) is a purpose-built wireless security research platform powered by the ESP32-S3 and running Bruce firmware, the open-source operating system built for offensive security and Red Team operations. WiFi deauth. Beacon spam. Evil portal. BLE scanning. Sub-GHz capture and replay. 2.4 GHz spectrum analysis. IR blasting. BadUSB payloads. All of it. One board. One firmware. No modules to swap. No accessories to buy. No $200+ price tag.
This isn’t a dev board someone duct-taped a radio module to. The Smoochiee was designed from the ground up as a dedicated Bruce hardware platform. Dual onboard RF paths: a CC1101 sub-GHz transceiver covering 315/433/868/915 MHz and an nRF24L01+PA/LNA module for 2.4 GHz operations, both wired to dedicated SPI buses. An 8-element IR transmitter array with a TSOP4838 receiver. A 1.47″ IPS color display driven by an ST7789 controller. 16 addressable WS2812B RGB LEDs. Onboard battery management with the BQ25896 PMIC. A microphone for spectrum visualization. Five-button navigation. MicroSD storage. USB-C with native HID support for keyboard emulation attacks. And expansion headers for GPS and NFC modules when you need them.
Bruce firmware turns the hardware loose. WiFi tools include station scanning, deauthentication, beacon flooding, evil portal deployment, packet sniffing, ARP spoofing, host scanning with port detection, and Pwnagotchi integration. Bluetooth handles BLE device scanning, BadBLE script execution, and platform-targeted spam. The CC1101 delivers sub-GHz signal scanning, capture, replay, spectrum analysis, and custom frequency configuration. The nRF24 covers 2.4 GHz analysis and operations. Infrared runs TV-B-Gone, custom protocol transmission (NEC, SIRC, Samsung32, RC5, RC6), and signal recording. And the onboard JavaScript interpreter lets you write and deploy custom payloads in the field without recompiling firmware.
The entire platform is open source. Hardware schematics, BOM, Gerber files, firmware source, all of it. Published under the CERN Open Hardware License. Build your own. Modify the design. Fork the firmware. Or just flash it from the Bruce web flasher and start working.
Key Specs:
- MCU: ESP32-S3-WROOM-1 N16R8 (Dual-Core Xtensa LX7 @ 240 MHz)
- Memory: 16MB Flash / 8MB Octal PSRAM
- Display: 1.47″ IPS TFT, 170×320, ST7789 controller
- Sub-GHz RF: CC1101 transceiver (315/433/868/915 MHz)
- 2.4 GHz RF: nRF24L01+PA/LNA (E01-2G4M27SX)
- WiFi: 802.11 b/g/n (2.4 GHz, onboard ESP32-S3)
- Bluetooth: BLE 5.0 (onboard ESP32-S3)
- IR: 8x IR26-51C transmitter LEDs + TSOP4838 receiver (38 kHz)
- LEDs: 16x WS2812B addressable RGB
- Audio: Onboard buzzer + I2S microphone
- Haptic: Vibration motor
- Storage: MicroSD card slot
- Power: USB-C input, BQ25896 PMIC with Li-ion battery charging
- Regulation: LT1963A 3.3V LDO + DC-DC boost to 5V
- I/O Expansion: AW9523 GPIO expander
- Input: 5-way navigation + select button + power slide switch
- Expansion: I2C/UART headers for GPS module (ATGM336H) and NFC module
- USB: Native USB with HID/BadUSB keyboard emulation
- Firmware: Bruce (open-source, web-flashable)
- License: CERN-OHL-P-2.0 (Permissive Open Hardware)
What Bruce firmware can do:
- WiFi: Scan, deauth, beacon spam, evil portal, packet sniff, ARP spoof, host/port scan, WireGuard tunnel, SSH/Telnet, Pwnagotchi/Pwngrid
- Bluetooth: BLE scan, BadBLE scripts, keyboard emulation, platform-targeted BLE spam (iOS, Android, Windows, Samsung)
- Sub-GHz (CC1101): Signal scan, capture, replay, spectrum analysis, custom frequency/modulation, RAW record/playback
- 2.4 GHz (nRF24): Spectrum analysis, channel scanning, NRF24 operations
- Infrared: TV-B-Gone, custom protocol TX/RX (NEC, SIRC, Samsung32, RC5, RC6), signal recording
- USB: BadUSB keyboard injection, HID emulation
- Expansion: NFC read/write/emulate (with external module), GPS wardriving (with external module), FM radio
- Scripting: Onboard JavaScript interpreter for field-deployable custom payloads
▌README.TXT – INSTRUCTIONS FOR USE
Compatibility: The Bruce PCB V2 (Smoochiee) is a standalone wireless security research platform. It is compatible with the Bruce firmware ecosystem and can be flashed directly from the Bruce web flasher at bruce.computer. No additional software installation is required for basic operation.
Step 1: Inspect Remove the board from packaging. Inspect the USB-C port, display, and all antenna connectors for shipping damage. Verify the power slide switch moves freely.
Step 2: Flash Firmware Connect the board to your computer via USB-C. Navigate to bruce.computer in a Chromium-based browser (Chrome, Edge, Brave). Select the Smoochiee board profile and flash the latest Bruce firmware directly to the device. The web flasher handles everything. No IDE, no toolchain, no command line required.
Step 3: Power On Slide the power switch to ON. The display will boot into the Bruce main menu. Navigate using the 5-way button cluster. If running on USB power without a battery installed, the board operates normally but will not retain power when disconnected.
Step 4: Install Battery (Optional) The BQ25896 PMIC supports direct Li-ion/Li-Po battery connection for portable operation. Connect a 3.7V lithium cell to the battery terminals. The PMIC handles charging via USB-C automatically. A 1000mAh cell provides approximately 2-3 hours of active use depending on radio activity.
Step 5: Connect Antennas For sub-GHz operations, connect a 433 MHz antenna to the CC1101 module’s antenna port. For 2.4 GHz nRF24 operations, connect a 2.4 GHz antenna to the nRF24 module’s antenna port. WiFi and Bluetooth use the ESP32-S3’s onboard PCB antenna and require no external connection.
Step 6: Expand (Optional) The board exposes I2C and UART headers for optional expansion modules. Connect an ATGM336H GPS module for wardriving and location-tagged captures. Connect a PN532 or ST25R3916 NFC module for RFID/NFC read, write, clone, and emulate operations. Modules connect directly to the labeled header pins.
PRO TIP: The Bruce firmware’s built-in JavaScript interpreter lets you write custom attack scripts and deploy them without recompiling. Drop your .js files on the MicroSD card, navigate to the script runner, and execute. Test your payloads in the field, iterate on the fly, redeploy in seconds. No laptop required.
▌DEBUG LOG – TROUBLESHOOTING
ISSUE: Board does not power on / no display output. FIX: Verify the power slide switch is in the ON position. If powered via USB-C, try a different cable and port. Some USB cables are charge-only and do not provide data or sufficient current. If a battery is installed, verify polarity at the battery connector. The BQ25896 has reverse polarity protection, but an incorrectly wired battery will not power the board.
ISSUE: Firmware flash fails / web flasher does not detect the board. FIX: Use a Chromium-based browser (Chrome, Edge, Brave). Firefox and Safari do not support WebSerial. Ensure no other application (Arduino IDE, serial monitor, PlatformIO) has the COM port open. On Windows, you may need to install the ESP32-S3 USB driver. On Linux, verify your user is in the dialout group. Try holding the BOOT button while connecting USB to force the board into download mode.
ISSUE: CC1101 sub-GHz not detecting signals / no sub-GHz functionality. FIX: Verify a 433 MHz antenna is connected to the CC1101 module. Without an antenna, the CC1101 has almost zero receive sensitivity. Also confirm you are tuned to an active frequency within the CC1101’s supported range. The module covers 300-928 MHz but performance varies by band. 433 MHz and 915 MHz are the strongest bands for this module.
ISSUE: WiFi deauth / beacon spam not working. FIX: WiFi attacks require the ESP32-S3’s WiFi radio, which operates on 2.4 GHz only. 5 GHz networks are not visible or targetable. Verify your target network is operating on a 2.4 GHz channel. Also note that some modern access points implement 802.11w (Protected Management Frames), which mitigates deauthentication attacks.
ISSUE: IR blaster range is limited. FIX: The 8-element IR LED array provides significantly more power and coverage than single-LED designs, but IR is still line-of-sight. Point the board directly at the target device. Reflective surfaces (white walls, ceilings) can extend effective range through bounce. Ambient sunlight and fluorescent lighting generate IR noise that reduces range. Indoor performance will always exceed outdoor.
ISSUE: MicroSD card not recognized. FIX: Format the card as FAT32. The firmware does not support exFAT or NTFS. Cards larger than 32GB may need to be formatted with a third-party tool (SD Card Formatter or similar) to force FAT32. Insert the card with the board powered off, then power on.
ISSUE: USB BadUSB / HID not working on target machine. FIX: The ESP32-S3 uses native USB, not a USB-UART bridge. Some machines require a moment to enumerate the HID device after connection. Wait 2-3 seconds before executing payloads. On locked machines, the keyboard injection cannot bypass the lock screen. Ensure the target is at an unlocked desktop or login prompt.
ISSUE: Battery drains quickly during active scanning. FIX: Continuous WiFi scanning, sub-GHz monitoring, and RGB LED animation draw significant current. Disable RGB LEDs in the Bruce settings menu to extend battery life. Reduce display brightness. For extended field sessions, use a USB power bank connected to the USB-C port.
▌SYS.WARN – WARNINGS, HAZARDS & DISCLAIMERS
LEGAL WARNING – READ THIS ENTIRE SECTION.
This device is a wireless security research platform with capabilities that may be regulated, restricted, or prohibited depending on your jurisdiction, authorization level, and intended use. Possession of this device is legal. Misuse of its capabilities is not.
Authorized Use Only. The offensive security features of this device and its firmware (including but not limited to WiFi deauthentication, beacon spoofing, evil portal deployment, BLE spam, sub-GHz signal capture and replay, and USB HID injection) are designed exclusively for use by authorized security professionals, penetration testers, and researchers operating under explicit written authorization from the system or network owner. Unauthorized access to computer networks and systems is a federal crime under the Computer Fraud and Abuse Act (18 U.S.C. Section 1030). Unauthorized interception of electronic communications is prohibited under the Electronic Communications Privacy Act (18 U.S.C. Section 2511).
WiFi Deauthentication. Transmitting deauthentication frames against networks you do not own or have explicit authorization to test may violate FCC rules regarding intentional interference (47 U.S.C. Section 333) and applicable state and federal computer crime statutes. Do not use this feature on networks without written permission from the network owner.
Sub-GHz RF Transmission. The CC1101 module is capable of transmitting on frequencies that may require licensing or authorization in your jurisdiction. Transmission on amateur radio frequencies requires a valid amateur radio license. Replay of captured signals (garage doors, car key fobs, alarm systems, etc.) against systems you do not own is illegal in most jurisdictions. The end user is solely responsible for compliance with all applicable RF transmission regulations.
USB HID / BadUSB. Deploying keyboard injection payloads against computer systems without authorization constitutes unauthorized access under federal and state law. This feature is intended for authorized penetration testing only.
International Users. Wireless security research regulations vary significantly by country. Some jurisdictions prohibit possession of devices with offensive security capabilities, regardless of intent. Users outside the United States are solely responsible for understanding and complying with their local laws.
Open Source Software. This device runs open-source firmware (Bruce) developed and maintained by the community. Rabbit-Labs LLC does not develop, maintain, or control the Bruce firmware. Firmware updates, features, and security patches are provided by the Bruce project. Rabbit-Labs LLC makes no warranty regarding firmware functionality, security, or fitness for any particular purpose.
Not a Toy. This product contains electronic components, radio frequency transmitters, lithium battery management circuits, and infrared emitters. Keep out of reach of children.
Battery Safety. This device uses a lithium-ion/lithium-polymer battery managed by the BQ25896 PMIC. Do not puncture, crush, short-circuit, or expose the battery to temperatures above 60C (140F). Do not charge unattended for extended periods. Use only compatible 3.7V lithium cells. Dispose of batteries in accordance with local regulations.
ESD Sensitivity. The board contains exposed RF modules, connectors, and semiconductor components that are sensitive to electrostatic discharge. Handle with appropriate ESD precautions.
Intended Use. This product is designed for use by wireless security researchers, authorized penetration testers, RF engineers, embedded systems developers, and electronics enthusiasts engaged in lawful research, testing, and experimentation. Rabbit-Labs LLC does not condone, support, or encourage any illegal use of this product or its firmware capabilities.
Disclaimer. This product is sold “as-is” for use by qualified individuals. Rabbit-Labs LLC makes no warranty, express or implied, regarding fitness for a particular purpose. The end user assumes all responsibility for compliance with applicable laws and for any consequences resulting from the use or misuse of this device. Maximum liability shall not exceed the purchase price of the product.
© Rabbit-Labs LLC. All rights reserved. The Rabbit-Labs name and logo are trademarks of Rabbit-Labs LLC. Bruce firmware is an independent open-source project and is not affiliated with Rabbit-Labs LLC.










Reviews
There are no reviews yet