Skip to product information
1 of 5

PINGEQUA

5Ghost Wifi Devboard for Flipper Zero - BW16 RTL8720DN Black

5Ghost Wifi Devboard for Flipper Zero - BW16 RTL8720DN Black

Regular price $39.99 USD
Regular price $45.98 USD Sale price $39.99 USD
Sale Sold out
Shipping calculated at checkout.
PINGEQUA · Dual-Band Wi-Fi Lab

5Ghost WiFi Lab

Real 2.4 GHz + 5 GHz Wi-Fi recon for Flipper Zero. Preloaded. Plug in and go.

An RTL8720DN (BW16) dual-band board that finally puts the 5 GHz radio to work — shipped preloaded with the 5Ghost WiFi Lab app. Dock it on the Flipper GPIO header: no wiring, no flashing, no serial commands. One clean app does the scanning, the handshake capture, the channel mapping, and the captive portal on both bands.

  • Real 5 GHz. Scan, capture, and map a band 2.4 GHz-only tools physically cannot see.
  • PMF / WPA3-aware. Flags the APs that ignore deauth up front, not after you waste time.
  • Handshake → PCAP, on device. WPA/WPA2 4-way to SD, crackable in hashcat / aircrack-ng.
  • Channel Map. Dual-band congestion view that points at the clear channel.
  • Evil Portal. Built-in pages, bundled demos, or your own HTML from the SD card.
  • One .fap, three firmwares. Official · Momentum · Unleashed.
// 01 · How it works

A 5 GHz radio, and an app that knows what to do with it.

Two halves of one tool — the board does the radio, the Flipper runs the brains.

Your Flipper Zero has no Wi-Fi radio of its own. 5Ghost adds one, a genuine dual-band RTL8720DN, and drives it entirely from a native Flipper app over GPIO UART. Nothing runs on a laptop; the Flipper is the host.

FLIPPER ZERO — host, 128×64 UI
5Ghost WiFi Lab .fap

GPIO · UART (TX/RX) + 5V/GND
RTL8720DN (BW16) — preloaded firmware
├─ 2.4 GHz radio · 802.11 b/g/n
└─ 5 GHz radio · 802.11 a/nthe part other tools skip

That GPIO link is the whole install: dock the board, copy one .fap to the SD card, and open the app. The board ships with its firmware already flashed.

// 02 · Inside the app

Seven tools, one clean screen.

Purpose-built for the 128×64 display, not a wall of serial commands.
  • Dual-band ScanLists 2.4 GHz and 5 GHz APs with signal, encryption, precise PMF (capable / required), WPA3 detection, and same-SSID mesh markers.
  • Channel MapCongestion view across both bands with the least-busy channel highlighted. Pick a clear channel, or find where the targets are.
  • Capture HandshakeForces a reconnect and grabs the WPA/WPA2 4-way handshake on 5 GHz, written as a standard PCAP to SD. Drop straight into hashcat (22000) or aircrack-ng.
  • Evil PortalCaptive-portal credential capture with built-in pages, bundled demo portals, or your own HTML from the SD card. Auto-opens on iOS.
  • PMF-aware DeauthDeauth on 2.4 GHz + 5 GHz that tells you when a target is 802.11w / WPA3-protected (deauth-immune) instead of failing silently. Hits every same-SSID mesh node in one pass.
  • Create AP · BeaconStand up a real joinable soft AP with the captive portal, or flood custom / random / Rickroll beacon frames.
  • Everything to SDScans (CSV), captured credentials, and handshakes (PCAP) all save to /ext/apps_data/5ghost/ with on-screen save confirmation.
// 03 · Why 5 GHz changes the game

Most Flipper Wi-Fi tools cannot see half the air.

The popular ESP32 boards have no 5 GHz radio. That is a hardware limit, not a setting.
2.4 GHz tool · ESP32 / Marauder-class

Half the spectrum, blind to the rest

  • No 5 GHz radio, so they cannot scan or target modern 5 GHz networks at all
  • No clear indication of which APs are PMF / WPA3 deauth-immune
  • Handshake capture is often unreliable on crowded 2.4 GHz
  • Often a wall of serial commands or a separate web UI
VS
5Ghost · RTL8720DN (BW16)

Both bands, on one board, in one app

  • Native 5 GHz scan, Channel Map, handshake capture, and deauth support
  • Parses each beacon's RSN IE to flag WPA3-SAE / 802.11w up front
  • Routes handshake capture through 5 GHz, where it lands more reliably
  • One native Flipper app, three firmwares, nothing to wire
// 04 · Quick start

Three steps from box to first scan.

The board is preloaded. There is nothing to flash.
  1. Dock the board. Seat the 5Ghost module on your Flipper Zero GPIO header (top pins). The 4-wire UART link is the only connection.
  2. Copy the app. Download the latest .fap from GitHub Releases and place it on your Flipper SD card under /ext/apps/GPIO/.
  3. Open it. On the Flipper, go to Apps → GPIO → 5Ghost WiFi Lab. The header shows Official when the board is detected.
// 05 · Compatibility

Built for one host, runs on every Flipper firmware.

One universal .fap that avoids the APIs disabled by official firmware, so it loads cleanly everywhere.
Verified on
  • Flipper Zero (GPIO / UART)
  • Official firmware
  • Momentum firmware
  • Unleashed firmware
Not a fit for
  • Other BW16 / RTL8720DN boards with different firmware or pinout
  • ESP32 Wi-Fi boards with no 5 GHz radio
  • Standalone use, because the Flipper is the host
// 06 · Specifications

The numbers that matter.

Radio
Chipset RTL8720DN (BW16)
Wi-Fi bands 2.4 GHz + 5 GHz · 802.11 a/b/g/n
Bluetooth BLE 5.0
Antenna Onboard PCB antenna (compact)
Interface
Host link Flipper Zero GPIO header · UART (TX/RX) + 5V/GND
Form factor Matches the Flipper Zero footprint
Software
Module firmware 5Ghost, preloaded (browser re-flash available)
Flipper app 5Ghost WiFi Lab .fap · Official / Momentum / Unleashed
App license MIT (open-source companion app)
In the box
Included 1 × 5Ghost dual-band board (preloaded)
Not included Flipper Zero host device (shown for reference)
// 07 · Firmware & recovery

Ships preloaded, with browser recovery if you ever need it.

You normally do not need to flash anything. This is the safety net.

The board leaves the factory with 5Ghost firmware already installed. The only thing you normally add is the Flipper .fap from Quick Start. If the module firmware is interrupted mid-update, corrupted, or needs to be restored, you can re-flash it from a web browser with no Arduino toolchain or command line.

  1. Open the recovery flasher. Visit flash.pingequa.com/devices/bw16-5ghost in Chrome or Edge on desktop, or Chrome on Android. Safari and Firefox do not support the required Web Serial API.
  2. Connect the board. Plug the 5Ghost board into your computer with a USB-C data cable, click Connect, and choose the port. If required by your OS, install the CH340 serial driver.
  3. Flash. Click Flash. It enters download mode automatically; if that fails, hold BOOT, tap RESET, release BOOT, and reconnect. A full image takes a few minutes at 115200 baud.

The flasher and firmware image are hosted by PINGEQUA, and the recovery page shows the latest device-specific steps and status.

// 08 · Honest limits

What it cannot do, stated clearly.

Overpromising creates refunds. Here is the actual boundary.
  • WPA3-SAE cannot be cracked offline. SAE (Dragonfly) is designed so a captured handshake has no offline-crackable hash. 5Ghost detects WPA3 and tells you when it is out of reach.
  • PMF / WPA3 APs cannot be deauthed. That is 802.11w working as designed. 5Ghost tells you instead of failing silently.
  • Mesh roaming is hard. Same-channel mesh nodes are hit in one pass; cross-channel 802.11r roaming is still difficult to suppress fully on single-radio hardware.
  • Handshake capture runs on 5 GHz. On 2.4 GHz, this chip often cannot hear the client uplink consistently, so capture uses 5 GHz.
  • Android captive auto-open can be blocked by Private DNS / DoH; the portal still appears when the user opens any HTTP page.
// 09 · FAQ

Real questions, straight answers.

Q.01Does it really do 5 GHz, or is that just marketing?

Really. The RTL8720DN (BW16) has a native 5 GHz radio, so 5Ghost scans, maps congestion, captures handshakes, and deauths on 5 GHz. Popular ESP32-based Flipper Wi-Fi tools cannot do this because their chips have no 5 GHz radio.

Q.02Do I have to flash firmware or wire anything?

No. The board ships preloaded with 5Ghost firmware. Dock it on the Flipper GPIO header and copy one .fap file to the SD card. No soldering, jumper wires, or toolchain are required.

Q.03Which Flipper Zero firmwares does it work on?

All three major firmwares: Official, Momentum, and Unleashed. It is a single universal .fap build.

Q.04Can it crack WPA3?

No. WPA3-SAE is designed so a captured handshake has no crackable offline hash. For WPA/WPA2 networks, 5Ghost captures the standard 4-way handshake to PCAP for use in tools like hashcat or aircrack-ng.

Q.05Onboard antenna or 8 dBi external, which should I buy?

Same board, same firmware, same app. The onboard PCB antenna version keeps a compact Flipper footprint, while the external-antenna version trades size for more reach.

Q.06Does it work on its own, without a Flipper Zero?

No. It is a companion module. The Flipper Zero is the host and is not included in this listing.

Q.07Can I use my own captive-portal page?

Yes. Place a self-contained .html file on the Flipper SD card and serve it through Evil Portal.

Q.08My deauth did not work on some networks. Is it broken?

Almost certainly not. Those networks are usually PMF (802.11w) or WPA3 protected, which makes them immune to deauth by design.

Q.09Is this legal to use?

The device is sold for authorized security testing and education. You are responsible for using it lawfully and complying with local radio regulations.

Q.10How do I restore the firmware if the board stops responding?

Use the browser recovery flasher at flash.pingequa.com/devices/bw16-5ghost in Chrome or Edge, connect the board with a USB-C data cable, then click Connect and Flash.

Shipping & Delivery

We ship globally. Orders are typically processed within 48 hours. Estimated delivery: 7-15 business days depending on your region.

Warranty & Returns

14-day return policy for unused items. Our hardware is backed by a limited warranty against manufacturing defects. (Note: Damage from improper flashing or overvoltage is not covered).

View full details

Official Docs