PINGEQUA
5Ghost Placa Wi-Fi para Flipper Zero – BW16 Antena externa
5Ghost Placa Wi-Fi para Flipper Zero – BW16 Antena externa
No se pudo cargar la disponibilidad de retiro
5Ghost WiFi Lab
An RTL8720DN (BW16) dual-band board that finally puts the 5 GHz radio to work — shipped preloaded with the 5Ghost WiFi Lab app. Dock it on the Flipper GPIO header: no wiring, no flashing, no serial commands. One clean app does the scanning, the handshake capture, the channel mapping, and the captive portal on both bands.
- Real 5 GHz. Scan, capture, and map a band 2.4 GHz-only tools physically cannot see.
- PMF / WPA3-aware. Flags the APs that ignore deauth up front, not after you waste time.
- Handshake → PCAP, on device. WPA/WPA2 4-way to SD, crackable in hashcat / aircrack-ng.
- Channel Map. Dual-band congestion view that points at the clear channel.
- Evil Portal. Built-in pages, bundled demos, or your own HTML from the SD card.
-
One
.fap, three firmwares. Official · Momentum · Unleashed.
A 5 GHz radio, and an app that knows what to do with it.
Your Flipper Zero has no Wi-Fi radio of its own. 5Ghost adds one, a genuine dual-band RTL8720DN, and drives it entirely from a native Flipper app over GPIO UART. Nothing runs on a laptop; the Flipper is the host.
│ 5Ghost WiFi Lab .fap
│
▼ GPIO · UART (TX/RX) + 5V/GND
RTL8720DN (BW16) — preloaded firmware
├─ 2.4 GHz radio · 802.11 b/g/n
└─ 5 GHz radio · 802.11 a/n ← the part other tools skip
That GPIO link is the whole install: dock the board, copy one .fap to the SD card, and open the app. The board ships with its firmware already flashed.
Seven tools, one clean screen.
- Dual-band ScanLists 2.4 GHz and 5 GHz APs with signal, encryption, precise PMF (capable / required), WPA3 detection, and same-SSID mesh markers.
- Channel MapCongestion view across both bands with the least-busy channel highlighted. Pick a clear channel, or find where the targets are.
- Capture HandshakeForces a reconnect and grabs the WPA/WPA2 4-way handshake on 5 GHz, written as a standard PCAP to SD. Drop straight into hashcat (22000) or aircrack-ng.
- Evil PortalCaptive-portal credential capture with built-in pages, bundled demo portals, or your own HTML from the SD card. Auto-opens on iOS.
- PMF-aware DeauthDeauth on 2.4 GHz + 5 GHz that tells you when a target is 802.11w / WPA3-protected (deauth-immune) instead of failing silently. Hits every same-SSID mesh node in one pass.
- Create AP · BeaconStand up a real joinable soft AP with the captive portal, or flood custom / random / Rickroll beacon frames.
-
Everything to SDScans (CSV), captured credentials, and handshakes (PCAP) all save to
/ext/apps_data/5ghost/with on-screen save confirmation.




Most Flipper Wi-Fi tools cannot see half the air.
Half the spectrum, blind to the rest
- No 5 GHz radio, so they cannot scan or target modern 5 GHz networks at all
- No clear indication of which APs are PMF / WPA3 deauth-immune
- Handshake capture is often unreliable on crowded 2.4 GHz
- Often a wall of serial commands or a separate web UI
Both bands, on one board, in one app
- Native 5 GHz scan, Channel Map, handshake capture, and deauth support
- Parses each beacon's RSN IE to flag WPA3-SAE / 802.11w up front
- Routes handshake capture through 5 GHz, where it lands more reliably
- One native Flipper app, three firmwares, nothing to wire
Three steps from box to first scan.
- Dock the board. Seat the 5Ghost module on your Flipper Zero GPIO header (top pins). The 4-wire UART link is the only connection.
- Copy the app. Download the latest
.fapfrom GitHub Releases and place it on your Flipper SD card under/ext/apps/GPIO/. - Open it. On the Flipper, go to
Apps → GPIO → 5Ghost WiFi Lab. The header showsOfficialwhen the board is detected.
Built for one host, runs on every Flipper firmware.
.fap that avoids the APIs disabled by official firmware, so it loads cleanly everywhere.- Flipper Zero (GPIO / UART)
- Official firmware
- Momentum firmware
- Unleashed firmware
- Other BW16 / RTL8720DN boards with different firmware or pinout
- ESP32 Wi-Fi boards with no 5 GHz radio
- Standalone use, because the Flipper is the host
The numbers that matter.
| Radio | |
| Chipset | RTL8720DN (BW16) |
| Wi-Fi bands | 2.4 GHz + 5 GHz · 802.11 a/b/g/n |
| Bluetooth | BLE 5.0 |
| Antenna | Onboard PCB antenna (compact) |
| Interface | |
| Host link | Flipper Zero GPIO header · UART (TX/RX) + 5V/GND |
| Form factor | Matches the Flipper Zero footprint, pocketable |
| Software | |
| Module firmware | 5Ghost, preloaded (browser re-flash available) |
| Flipper app | 5Ghost WiFi Lab .fap · Official / Momentum / Unleashed |
| App license | MIT (open-source companion app) |
| In the box | |
| Included | 1 × 5Ghost dual-band board (preloaded) |
| Not included | Flipper Zero host device (shown for reference) |
Ships preloaded, with browser recovery if you ever need it.
The board leaves the factory with 5Ghost firmware already installed. The only thing you normally add is the Flipper .fap from Quick Start. If the module firmware is interrupted mid-update, corrupted, or needs to be restored, you can re-flash it from a web browser with no Arduino toolchain or command line.
- Open the recovery flasher. Visit flash.pingequa.com/devices/bw16-5ghost in Chrome or Edge on desktop, or Chrome on Android. Safari and Firefox do not support the required Web Serial API.
- Connect the board. Plug the 5Ghost board into your computer with a USB-C data cable, click
Connect, and choose the port. If required by your OS, install the CH340 serial driver. - Flash. Click
Flash. It enters download mode automatically; if that fails, holdBOOT, tapRESET, releaseBOOT, and reconnect. A full image takes a few minutes at 115200 baud.
The flasher and firmware image are hosted by PINGEQUA, and the recovery page shows the latest device-specific steps and status.
What it cannot do, stated clearly.
- WPA3-SAE cannot be cracked offline. SAE (Dragonfly) is designed so a captured handshake has no offline-crackable hash. 5Ghost detects WPA3 and tells you when it is out of reach.
- PMF / WPA3 APs cannot be deauthed. That is 802.11w working as designed. 5Ghost tells you instead of failing silently.
- Mesh roaming is hard. Same-channel mesh nodes are hit in one pass; cross-channel 802.11r roaming is still difficult to suppress fully on single-radio hardware.
- Handshake capture runs on 5 GHz. On 2.4 GHz, this chip often cannot hear the client uplink consistently, so capture uses 5 GHz.
- Android captive auto-open can be blocked by Private DNS / DoH; the portal still appears when the user opens any HTTP page.
Real questions, straight answers.
Q.01Does it really do 5 GHz, or is that just marketing?
Really. The RTL8720DN (BW16) has a native 5 GHz radio, so 5Ghost scans, maps congestion, captures handshakes, and deauths on 5 GHz. Popular ESP32-based Flipper Wi-Fi tools cannot do this because their chips have no 5 GHz radio.
Q.02Do I have to flash firmware or wire anything?
No. The board ships preloaded with 5Ghost firmware. Dock it on the Flipper GPIO header and copy one .fap file to the SD card. No soldering, jumper wires, or toolchain are required.
Q.03Which Flipper Zero firmwares does it work on?
All three major firmwares: Official, Momentum, and Unleashed. It is a single universal .fap build.
Q.04Can it crack WPA3?
No. WPA3-SAE is designed so a captured handshake has no crackable offline hash. For WPA/WPA2 networks, 5Ghost captures the standard 4-way handshake to PCAP for use in tools like hashcat or aircrack-ng.
Q.05Onboard antenna or 8 dBi external, which should I buy?
Same board, same firmware, same app. The onboard PCB antenna version keeps a compact Flipper footprint, while the external-antenna version trades size for more reach.
Q.06Does it work on its own, without a Flipper Zero?
No. It is a companion module. The Flipper Zero is the host and is not included in this listing.
Q.07Can I use my own captive-portal page?
Yes. Place a self-contained .html file on the Flipper SD card and serve it through Evil Portal.
Q.08My deauth did not work on some networks. Is it broken?
Almost certainly not. Those networks are usually PMF (802.11w) or WPA3 protected, which makes them immune to deauth by design.
Q.09Is this legal to use?
The device is sold for authorized security testing and education. You are responsible for using it lawfully and complying with local radio regulations.
Q.10How do I restore the firmware if the board stops responding?
Use the browser recovery flasher at flash.pingequa.com/devices/bw16-5ghost in Chrome or Edge, connect the board with a USB-C data cable, then click Connect and Flash.
Shipping & Delivery
Shipping & Delivery
We ship globally. Orders are typically processed within 48 hours. Estimated delivery: 7-15 business days depending on your region.
Warranty & Returns
Warranty & Returns
14-day return policy for unused items. Our hardware is backed by a limited warranty against manufacturing defects. (Note: Damage from improper flashing or overvoltage is not covered).
