mirror of
https://github.com/boku7/BokuLoader/
synced 2026-06-06 15:24:27 +00:00
d16ef491c0e28e1ab7d616270e48b4b6ddfc9a3b
BokuLoader - Cobalt Strike Reflective Loader
Cobalt Strike User-Defined Reflective Loader written in Assembly & C for advanced evasion capabilities.
Contributors: Bobby Cooke @0xBoku & Santiago Pecin @s4ntiago_p
Features
- Stomp MZ Magic Bytes
- Find-Self EggHunter
- Direct NT Syscalls via HellsGate & HalosGate
- PE Header Obfuscation
- PE String Replacement
- NOHEADERCOPY - Loader will not copy headers over to beacon. Decommits the first memory page which would normally hold the headers
- NoRWX - The Reflective loader writes beacon with Read & Write permissions and after resolving Beacons Import Table & Relocations, changes the .TEXT code section of Beacon to Read & Execute permissions
- XGetProcAddress for resolving symbols
- 100k UDRL Size
- Caesar Cipher for string obfuscation
- Prepend ASM Instructions
Project Origins
- Based on Stephen Fewer's incredible Reflective Loader project:
- Initially created while working through Renz0h's Reflective DLL videos from the Sektor7 Malware Developer Intermediate (MDI) Course
Usage
- Compile the BokuLoader Object file with
make - Start your Cobalt Strike Team Server
- Within Cobalt Strike, import the
BokuLoader.cnaAggressor script - Generate the x64 beacon (Attacks -> Packages -> Windows Executable (S))
- Use the Script Console to ensure BokuLoader was implemented in the beacon build
- Does not support x86 option. The x86 bin is the original Reflective Loader object file.
- Generating
RAWbeacons works out of the box. When using the Artifact Kit for the beacon loader, thestagesizevariable must be larger than the default.- See the Cobalt Strike User-Defined Reflective Loader documenation for additional information
Detection Guidance
- BokuLoader does not support the Cobalt Strike
sleep_maskoption.- This is due to the supported
userwx falsesettings hardcoded into BokuLoader. - Since the memory sections are either
RWorRX, this will cause sleep encryption to fail when attempting to write to the.textsection of beacon. - Analyzing the beacons process memory will reveal strings common to Cobalt Strike.
- This is due to the supported
- BokuLoader changes some commonly detected strings to new hardcoded values. These strings can be used to signature BokuLoader:
| Original Cobalt Strike String | BokuLoader Cobalt Strike String |
|---|---|
| ReflectiveLoader | djoiqnfkjlnslfmn |
| Microsoft Base Cryptographic Provider v1.0 | 12367321236742382543232341241261363163151d |
| (admin) | (tomin) |
| beacon | bacons |
- BokuLoader calls the following NT systemcalls to setup the loaded executable beacon memory:
NtAllocateVirtualMemory,NtProtectVirtualMemory,NtFreeVirtualMemory- These are called directly from the BokuLoader executable memory. These system calls are not backed by NTDLL memory.
- Setting userland hooks in
ntdll.dllwill not detect these systemcalls. - It may be possible to register kernelcallbacks using a kernel driver to monitor for the above system calls and detect their usage when they are not called from
ntdll.dll. - The BokuLoader itself will contain the
mov eax, r11d; syscall; retassembly instructions within its executable memory.
- The original beacon memory which loads beacon to a new memory location will be left in memory.
- This original memory will contain both the obfuscated beacon DLL header and the beacon itself.
- The executable beacon memory will not contain the beacon DLL header.
- It may be possible to scan memory to detect these duplicate memory regions.
- The loaded beacon memory is hardcoded as a
Private: Commitmemory region and is292KB.- The original beacon memory will be larger, as it also contains the
0x1000byte beacon DLL header, used for loading the beacon DLL into memory. - The memory section will be loaded at a
+0x1000offset. This is due to the first 0x1000 bytes of the memory being deallocated within BokuLoader.
- The original beacon memory will be larger, as it also contains the
- The BokuLoader source code is provided within the repository and can be used to create memory signatures.
- If you have additional detection guidance, please feel free to contribute by submitting a pull request.
Credits / References
Reflective Loader
- https://github.com/stephenfewer/ReflectiveDLLInjection
- Checkout these videos if you're interested in Reflective DLL:
HalosGate SysCaller
- Reenz0h from @SEKTOR7net
- Checkout Reenz0h's awesome courses and blogs!
- Best classes for malware development I have taken.
- Creator of the halos gate technique. His work was initially the motivation for this work.
- Sektor7 HalosGate Blog
HellsGate Syscaller
- @smelly__vx & @am0nsec ( Creators/Publishers of the Hells Gate technique )
- Could not have made my implementation of HellsGate without them :)
- Awesome work on this method, really enjoyed working through it myself. Thank you!
- https://github.com/am0nsec/HellsGate
- Link to the Hell's Gate paper: https://vxug.fakedoma.in/papers/VXUG/Exclusive/HellsGate.pdf
Cobalt Strike User Defined Reflective Loader
Great Resource for learning Intel ASM
ETW and AMSI Bypass
- @mariuszbit - for awesome idea to implement bypasses in reflective loader!
- @XPN Hiding Your .NET – ETW
- ajpc500/BOFs
- Offensive Security OSEP
Implementing ASM in C Code with GCC
- https://outflank.nl/blog/2020/12/26/direct-syscalls-in-beacon-object-files/
- https://www.cs.uaf.edu/2011/fall/cs301/lecture/10_12_asm_c.html
- http://gcc.gnu.org/onlinedocs/gcc-4.0.2/gcc/Extended-Asm.html#Extended-Asm
Cobalt Strike C2 Profile Generator
Languages
C
99.8%
Makefile
0.2%