Commit Graph
34 Commits
Author SHA1 Message Date
JYenn 765e609902 setup.py: drop unused os import (pyflakes clean across wrappers.py + setup.py) 2026-08-16 14:59:16 +01:00
JYenn d0b9b7da5a clickfix lure: rebuild to the real Cloudflare Turnstile challenge clone (per 0x204/ClickFix-Turnstile kit + MS Threat Intel binancepizza sample + inde.nz teardown): 'Just a moment...' title, light theme, 2.2s 'Checking if you are human' preloader before the widget appears, site-domain line, reCAPTCHA-style checkbox that turns #4285f4 with a checkmark, Ray ID footer, exact kit step wording, Verify button; dropped the dark overlay + observe code box (the '# comment' trick breaks -EncodedCommand, verified locally: 'Cannot process command because a command is already specified'); headless gate proven live - puppeteer navigator.webdriver + HeadlessChrome UA both blocked, trusted CDP click in real Edge lands the full 427-char command on the OS clipboard 2026-08-16 14:53:17 +01:00
JYenn b9038cf239 payload wrappers: clickfix_html format - fake Cloudflare 'Verify you are human' page that poisons the clipboard with a hidden PowerShell cradle on the checkbox click and shows Win+R / Ctrl+V / Enter steps; command rides XOR 0x83 + hex like the in-the-wild kits, headless and non-Windows visitors get a benign spinner (per 2026 ClickFix lures: Rapid7 DoubleDonut, MS Threat Intel, PhishEye BW kit); verified 61/61 in the end-to-end harness plus real-JS DOM run (both copy APIs fire, gate works) 2026-08-16 14:29:13 +01:00
JYenn 1776789ed7 payload wrappers: lnk opens an embedded decoy PDF before the cradle (decoy-first, per 2026 DPRK/Patchwork/MoonPeak LNK chains), lnk/polyglot_exe_zip now need pikepdf; docm/xlsm/pptm decoys upgraded (docx core props, xlsm currency format/bold header/widths, pptm fills template slide 0), decoy pool normalized to title/body pairs, html/polyglot_html pages show the decoy text; README: MOTW delivery notes + refreshed operator view screenshot (renamed MiseryOperatorView.png) 2026-08-16 04:53:04 +01:00
JYenn a88718429e payload wrappers: 9 filetype delivery formats via setup.py -p (docm/xlsm/pptm macros with real decoy content, lnk cradle, pdf attachment+OpenAction, OneDrive-style html smuggle, iso, exe+zip and exe+html polyglots), STAGE_URL option, --list-formats, per-format manifest entries, README section 2026-08-16 04:37:01 +01:00
JYenn e09954fcd9 loot command + dist artifacts: 'loot' dumps last STEAL_RESULT JSON raw (16384 cap, lock-guarded), setup.py emits dist/<OUT>.exe + <OUT>.manifest.json (config snapshot + sha256, no auth secret), --list-artifacts 2026-08-16 04:08:12 +01:00
JYenn 38990e708d console UX: msfconsole-style bot registry (per-bot key+outbox keyed by eph pubkey over the stateless beacon relay, so concurrent agents no longer trample one global key), bot select/list/all targeting, dynamic prompt, command history with up/down recall persisted to console_history.txt, TAB completion with double-tab listing; no-bot guard on target commands; shell/elevate system commands, agent crash logging, JPEG quality 90 2026-08-16 03:50:04 +01:00
JYenn d534533c72 headless browser sessions: --headless=new for interactive+ghost, CDP recovery ladder (reattach on detach, Page.reload revive, bounded relaunch), stale DevToolsActivePort/Singleton cleanup on launch, last-frame replay so the view never blacks out, unsafe-swiftshader; boxed console banner 2026-08-16 03:18:09 +01:00
JYenn 198f1fcdab elevation: silent UAC bypass (PEB masquerade + CMSTPLUA/ICMLuaUtil) and SYSTEM token theft; wire elevate command 2026-08-16 01:12:29 +01:00
JYenn 8e64b360d7 ghost: seed sign-in cookies via CDP; Edge ABE vtable fix, 24H2 syscall sizes, relay chunked bodies 2026-08-16 00:29:40 +01:00
JYenn 11ce3c0def ghost: call SetBackupState before PrepareForBackup (VSS_E_BAD_STATE otherwise) 2026-08-15 22:02:00 +01:00
JYenn b02758ed1e ghost: copy profiles from VSS snapshots with plain-copy fallback 2026-08-15 21:59:04 +01:00
JYenn 0f48e974fc comments: fix stale claims, dedupe rationales, trim essays across src 2026-08-15 21:43:49 +01:00
JYenn 4073f259f3 docs: rewrite README (features, quick start, build, layout); correct hidden-desktop claims 2026-08-15 15:28:50 +01:00
JYenn 480c89ce6e cdp: occluded-renderer freeze fix; reattach/relaunch recovery; ghost nav, hvnc quality 2026-08-15 15:14:31 +01:00
JYenn c9ce88e507 hvnc: serialize session under one lock; direct-to-canvas capture; kill-on-close job 2026-08-15 05:41:11 +01:00
JYenn c559212825 build result text once; drop crash.log from repo 2026-08-15 05:33:30 +01:00
JYenn e05dee39dd ghost: stop() cleanup guard; log stopped only once 2026-08-15 05:30:49 +01:00
JYenn 61b5cd0caf docs: correct session table for CDP-rendered interactive browser; tidy hvnc code 2026-08-15 05:18:14 +01:00
JYenn c17155dc7f hvnc: CDP-rendered interactive browser view (DirectComposition is ungdi-capturable on hidden desktops) 2026-08-15 04:01:05 +01:00
JYenn 8d25dc2b15 hvnc: real-profile browser (quoted user-data-dir, copy once per session), double-buffered view paint 2026-08-15 03:51:59 +01:00
JYenn 2fa69c5e75 style: trim comment bloat in hvnc input/capture paths 2026-08-15 03:42:47 +01:00
JYenn 5633e841ef hvnc: split keyboard into CHAR (text) vs KEYDOWN whitelist to kill double chars, conditional activation/MOUSEACTIVATE to kill double clicks, persistent capture canvas to kill black flicker, forward DBLCLK 2026-08-15 03:41:14 +01:00
JYenn eb11e8ae79 hvnc: correct input synthesis (client coords, key lparam, real focus), stable diff resync; ghost profile-copy, beacon jitter/batching, console view rework 2026-08-15 03:38:13 +01:00
JYenn e549daeb4d docs: list harvested browsers and apps in stealer bullet 2026-08-15 00:32:16 +01:00
JYenn 4a3e3f1307 docs: restore README image sections 2026-08-15 00:31:08 +01:00
JYenn f3587510c7 docs: rewrite README with a feature bullet list 2026-08-15 00:30:26 +01:00
JYenn 314905126a transport: dirty-tile frame encoding, only send changed pixels 2026-08-15 00:30:22 +01:00
JYenn a7f0b17fef transport: ECDH P-256 key agreement, drop baked-in master key
setup.py now generates a P-256 console keypair: the public half compiles into config.h, the private half persists to .misery_key (gitignored, chmod 600) and is loaded by the console at runtime. Agent and console agree a per-connection AES-256-GCM session key from an ECDH handshake (plaintext KEY_EXCHANGE frame on TCP, ephemeral-pubkey prefix on beacon polls), so no secret key material ships in a binary. KEY= option removed; --rotate-key rotates the keypair.
2026-08-14 23:14:06 +01:00
JYenn 68b88f52c7 docs: tighten README wording
Fix the Ek0m attribution before/after apostrophe, reword the WMI guard explanation so it says what it does, and swap 'reports in' for 'checks in'.
2026-08-14 22:25:04 +01:00
JYenn 009d7a2b1f agent: anti-analysis fingerprinting and self-healing WMI persistence
Add a user-mode environment check (CPUID, firmware tables, MAC OUIs, guest drivers, PEB flags, debug-port queries, tool scans) that gates the TCP reconnect backoff. Extend debugger_present() with ProcessDebugObjectHandle (0x1E). Add WMI event subscriptions (T1546.003): a 15-minute timer relaunch plus a Run-key guard that recreates a deleted value, backed by an idempotent Run write that cannot retrigger itself. Document both in the README.
2026-08-14 22:21:45 +01:00
JYenn 06cb9147c2 builder/ghost hardening: persist master key, sweep stale ghost profiles
setup.py saves and reuses the master key in .misery_key (gitignored, chmod 600) so rebuilds keep one key and deployed agents stay reachable; --rotate-key forces a fresh one. Ghost sessions now use unique per-process profile dirs and clean up leftovers from crashed sessions, including a partial-start cleanup when the browser fails to launch.
2026-08-14 22:21:41 +01:00
JYenn 0003817596 Console beacon transport: HTTP relay front-end, outbox queue, REGISTER on beacon poll 2026-08-14 20:44:04 +01:00
JYenn ff4dbf3f2b HVNC + Misery: hidden-desktop and ghosted browser sessions with encrypted C2 2026-08-14 20:21:41 +01:00