Flipper Zero 5 GHz Wi-Fi in 2026: 5Ghost (BW16) vs ESP32 Marauder vs ESP32-C5
Share
PINGEQUA Lab · Wi-Fi research · Updated 2026-09-01
5Ghost WiFi Lab is a dual-band 2.4 / 5 GHz Wi-Fi research tool for the Flipper Zero, built on the Realtek RTL8720DN (BW16) radio. This 2026 comparison is about jobs, not chip slogans: a preloaded BW16 field auditor with Guided Audit, a mature 2.4 GHz ESP32 Marauder, and ESP32-C5 boards that can scan 5 GHz without being the same capture workflow.
Can a Flipper Zero do 5 GHz Wi-Fi?
Not by itself. The Flipper Zero has no Wi-Fi radio. Every Wi-Fi feature is an add-on on the GPIO header, so the chip on that board decides which bands exist.
The common ESP32 parts — original ESP32, S2, S3, C3, C6 — are 2.4 GHz only. No firmware, including ESP32 Marauder, can invent a 5 GHz radio on those dies. That is still the hardware most “Flipper WiFi Devboard” listings ship.
Two dual-band paths exist in 2026:
- Realtek RTL8720DN (BW16) — native 2.4 + 5 GHz. This is the radio on 5Ghost.
- Espressif ESP32-C5 — dual-band Wi-Fi 6 on one radio (Espressif). This is the radio on Apex 5 and Scout Lite, and Marauder now publishes C5 binaries.
So “can a Flipper do 5 GHz?” is really “which board did you dock?” 5 GHz is not unique to 5Ghost. The useful difference is the workflow: a native Flipper app that treats capture as a task, versus a Marauder companion that treats 5 GHz as a C5 scan/deauth surface that is still maturing.
Flipper Zero WiFi Devboard vs 5Ghost vs Apex 5 vs Scout Lite
These are different products that happen to sit on the same GPIO header. Compare the job, then the sticker.
| Bare Flipper | Official / PINGEQUA ESP32-S2 + Marauder | Apex 5 (ESP32-C5) | Scout Lite (C5 + GPS) | 5Ghost BW16 | |
|---|---|---|---|---|---|
| Wi-Fi bands | None | 2.4 GHz | 2.4 + 5 GHz Wi-Fi 6 | 2.4 + 5 GHz Wi-Fi 6 | 2.4 + 5 GHz native |
| Preloaded | — | Official: flash Marauder yourself. PINGEQUA S2: yes | Marauder on C5 | Marauder + GPS | Yes — dock, copy one .fap |
| Native Flipper app | — | Marauder companion FAP | Marauder companion FAP | Marauder companion FAP | 5Ghost WiFi Lab (one .fap, three firmwares) |
| Guided Audit | No | No | No | No | Yes — app 2.7.4 picks handshake or PMKID |
| PMF / WPA3 flags | — | Not a headline Marauder feature | Depends on Marauder build | Depends on Marauder build | Beacon RSN parsed; deauth-immune APs labelled |
| BLE four-ecosystem trackers | No general BLE scanner for apps | Marauder BLE scan + spam | Marauder BLE | Marauder BLE | AirTag / Tile / SmartTag / Find My + nearby Flipper; then GATT / iBeacon / BadBLE |
| GPS / WiGLE | No | No | Onboard GPS (WarDrive: confirm V2) | Yes — L86-M33, WigleWifi CSV | No |
| Price (checked 2026-09-01) | Host only | Official $35, sold out on flipper.net. PINGEQUA $29.99 | $79 on Tindie | $64.98 | $39.99 onboard / $44.99 external |
Prices: PINGEQUA storefront JSON 2026-09-01 (S2 $29.99, 5Ghost $39.99–$44.99, Scout Lite $64.98, all available: true). Official board $35, Sold out the same day. Apex 5 $79 on Tindie (checked 2026-09-01; V1 and V2 listed).
ESP32 Marauder 5 GHz / ESP32-C5 Marauder
Marauder remains the largest open 2.4 GHz toolkit for Flipper-class ESP32 boards. Latest stable as of this writing is v1.15.1 (2026-08-24). The project now ships C5 binaries (including Dual Mini C5) and documents ESP32-C5 5 GHz support on the release page.
That does not turn an ESP32-S2 Devboard into a 5 GHz radio. If your board is S2/S3, Marauder is still 2.4 GHz. If your board is C5, you get dual-band scan on that chip — and, on boards such as Scout Lite, the vendor is explicit that 5 GHz is scan / enumeration, with handshake work staying on 2.4 GHz.
C5 5 GHz attacks (deauth, capture) have been the early part of this stack: batch-one Apex 5 units shipped without WarDrive according to CNX Software (2026-02-11); the current Tindie listing says V2 adds WarDrive. Treat C5 Marauder as “the chip can see 5 GHz,” not as “the same 5 GHz handshake path 5Ghost routes on BW16.”
Guided Audit is the 5Ghost task entry — C5 scan is not the same job
Guided Audit is orchestration, not a new radio. On 5Ghost app 2.7.4 it sits on the main menu under Channel Map. You pick an AP; the app chooses handshake or clientless PMKID from PMF state and whether stations are present. You do not pick the path. Firmware stays 2.7.3 — copy the new .fap; you do not reflash the board for this app.


The result is a short word: Complete / Partial / Unsupported / Timeout / Blocked. Complete is allowed only if a quality-gated PCAP or .22000 was written (plus audit_*.json). Partial is metadata, not a crackable capture. DFS channels are receive-only → Unsupported. Complete does not mean “this empty AP is guaranteed to fall.” Handshake and Capture PMKID stay on the menu when you want one path yourself.
That is the 5Ghost pitch as a dual-band field auditor: one docked board, one native app, a task that finishes with evidence on the SD card. A C5 Marauder that lists 5 GHz SSIDs is a different product, even when the frequency number matches.
Flipper Zero PMKID capture, handshake, and Evil Portal
Three tools people search as if they were one:
- Handshake — the WPA/WPA2 4-way. On 5Ghost this is routed over 5 GHz because this RTL chip often cannot hear the client’s M2/M4 uplink on 2.4 GHz. Needs a client that will reconnect. Exports PCAP.
-
Clientless PMKID — AUTHPROBE association to the AP, no client required. 5Ghost marks it beta. Only “Valid PMKID” writes
.22000. Not every WPA2 AP includes a usable PMKID. Marauder/GhostESP can obtain a PMKID by sniffing or deauthing a client; that is not the same clientless path. - Evil Portal — a captive portal for authorized testing (built-in pages, bundled demos, or your HTML). 5Ghost auto-opens on iOS; Android Private DNS can block auto-open. Walkthrough: Evil Portal setup.
None of these crack WPA3-SAE offline. SAE is designed so a captured handshake has no crackable hash. PMF-required networks ignore deauth. A tool that does not tell you that will waste your afternoon; 5Ghost flags it in the scan.
Flipper Zero AirTag / Find My detector
A bare Flipper’s official firmware does not expose a general BLE scanner to third-party apps (issue #2906, closed unimplemented). 5Ghost uses the BW16 radio: a passive sweep that names vendors, flags trackers across Apple AirTag, Tile, Samsung SmartTag, and Google Find My, and marks nearby Flipper Zeros. GATT recon, iBeacon spoof, and BadBLE HID are separate, active tools — authorized pairing tests only.
This is a recon feature on a Wi-Fi board, not a dedicated anti-tracking product. If BLE is the whole job, read the dedicated BLE scanner guide. Marauder also does BLE scan and spam; the ecosystems and Flipper-detect emphasis differ.
Best Flipper Zero WiFi board 2026 — options, not a trophy
There is no single best board. Choose by job:
- Need a reliable 5 GHz field audit on Flipper (PMF-aware scan, Guided Audit, 5 GHz handshake, evidence on SD) → 5Ghost BW16.
- Need the mature 2.4 GHz Marauder ecosystem and do not care about 5 GHz capture → official WiFi Devboard or PINGEQUA ESP32-S2 at $29.99.
- Need GPS-tagged dual-band wardrive / WiGLE → Scout Lite ($64.98). 5 GHz there is enumeration, not 5Ghost’s handshake path.
- Need C5 + sub-GHz + NRF24 on one paddle → Apex 5 ($79). Confirm V2 if you need WarDrive; Batch 1 did not ship it.
If you are still deciding whether you need 5 GHz at all, start with why 2.4 GHz is enough for most beginners. A longer buyer matrix lives in Best Flipper Zero WiFi Devboards 2026.
Official Flipper WiFi Devboard alternative
The official board is an ESP32-S2 wireless debugger that can run Marauder after you flash it. On 2026-09-01 it is $35 and sold out on flipper.net. A pin-compatible pre-flashed S2 (PINGEQUA, $29.99) is the drop-in alternative for that 2.4 GHz job. It is not a 5 GHz alternative. If the limitation you keep hitting is “my tool cannot see the 5 GHz SSID,” an S2 clone will not fix it — you need dual-band hardware, then you still pick 5Ghost vs C5 by workflow.
Bruce / GhostESP on Flipper
Bruce and GhostESP are ESP32 firmwares you flash onto hardware you supply, not Flipper-native apps in the 5Ghost sense.
- Bruce 1.16.1 (2026-08-11, AGPL-3.0) targets M5 / CYD-class devices. It is a standalone pentest OS, not a GPIO companion for Flipper. 5 GHz is C5/experimental in that ecosystem.
-
GhostESP v2.1.1 (2026-08-17, GPL-3.0) is Latest;
v2.1.2-pre2is a pre-release, not Latest. C5 5 GHz scan and deauth are documented. There is a Flipper companion app. It still is not Guided Audit on BW16.
All three projects are legitimate. The Flipper app is MIT; module firmware is licensed and distributed separately (see the project NOTICE.md). You get a preloaded board and a purpose-built 128×64 UI, not a Marauder-style fully open radio stack.
Honest limits (any of these tools)
- WPA3-SAE has no offline-crackable hash.
- PMF required ignores deauth.
- 5Ghost PMKID is beta; Complete is not a promise on an empty AP.
- 5Ghost handshake is the 5 GHz path; DFS is RX-only (firmware 2.7.3).
- Third-party BW16 boards are not supported.
- 5Ghost has no GPS; Scout Lite’s 5 GHz is scan-only.
Get dual-band 5 GHz on Flipper — or pick the other job
5Ghost ships preloaded. Dock GPIO, copy app 2.7.4, firmware 2.7.3 is enough. If you wanted Marauder on 2.4 GHz or GPS wardrive, those boards are linked too.
5Ghost BW16 → ESP32-S2 $29.99 → Scout Lite GPS →FAQ
Can a Flipper Zero do 5 GHz Wi-Fi?
Is 5Ghost the only Flipper board that can do 5 GHz?
What is Guided Audit?
Does ESP32 Marauder do 5 GHz?
Can any of these tools crack WPA3?
Is 5Ghost PMKID capture beta?
Does 5Ghost work on a third-party BW16 board?
Do I need to reflash 5Ghost firmware for app 2.7.4?
Can a Flipper detect AirTags?
What is the best Flipper Zero WiFi board in 2026?
Sources (accessed 2026-09-01): 5Ghost app v2.7.4 · firmware picker 2.7.3 at flash.pingequa.com · ESP32 Marauder v1.15.1 (2026-08-24) · Bruce 1.16.1 (2026-08-11) · GhostESP v2.1.1 (2026-08-17 Latest) · ESP32-C5 Espressif · Apex 5 Tindie $79 · Apex Batch 1 WarDrive gap CNX 2026-02-11 · official Devboard flipper.net $35 sold out · Flipper BLE scanner #2906. Related: 5Ghost feature how-to (v2.7.0) · ESP32-C5 wardriving · GPS + WiGLE 2026.
For authorized security testing and education only. Test only networks and devices you own or have explicit written permission to test. You are responsible for compliance with applicable laws and radio regulations (FCC Part 15 in the US). “Flipper Zero,” “ESP32 Marauder,” “Bruce,” and “GhostESP” are referenced for compatibility and comparison; PINGEQUA is independent and not affiliated with or endorsed by their owners.