Serverloses C2-Transport-Plugin für AdaptixC2 v1.2, das AWS Lambda + DynamoDB als Relay-Infrastruktur verwendet.

Serverless-C2-Transport-Plugin für AdaptixC2 v1.2, das AWS Lambda + DynamoDB als Relay-Infrastruktur verwendet. Agent-Traffic erscheint als ausgehendes HTTPS zu AWS-Endpunkten und erfordert keine eingehenden Ports oder öffentlichen IPs auf dem C2-Server.
Kharon Agent (target)
|
| HTTPS GET/POST (outbound only, randomly alternated)
v
AWS Lambda Function URL (stateless relay)
|
| Store inbound / Poll outbound (up to 8s)
v
DynamoDB (inbound + outbound tables)
^
| Poll every 5 seconds
|
Listener Plugin (inside AdaptixC2)
|
| TsAgent API + TsExtenderData (key persistence)
v
AdaptixC2 Teamserver + UI
Datenfluss:
inboundoutbound bis zu 8 Sekunden lang ab (überbrückt die asynchrone Lücke für die Registrierung)inbound nach unverarbeiteten Datensätzen aboutbound| Komponente | Pfad | Zweck |
|---|---|---|
| Kharon-Agent | agent/ | Mitgeliefertes Kharon-Implant (C++-Quellcode) |
| Terraform | deploy/aws/ | Lambda + DynamoDB + IAM + KMS-Infrastruktur |
| Lambda-Relay | deploy/aws/lambda/ | Zustandsloser HTTP-zu-DynamoDB-Proxy mit Outbound-Polling |
| Listener-Plugin | listener/ | AdaptixC2-Plugin, DynamoDB-Polling, Kharon-Protokoll-Bridge |
| Kharon-Konfigurationen | kharon/ | AXS-Befehlsregistrierung und -Konfiguration für Agent-/Listener-Extender |
| Patches | patches/ | AdaptixC2-Quellcode-Patches für BeaconServerless-Unterstützung |
| Profile | profiles/ | Malleable-HTTP-Profil für Lambda-URL |
| Skripte | scripts/ | Installieren, Bauen, Bereitstellen, Deinstallieren |
aws configure)apt install clang lldapt install nasmapt install binutils-mingw-w64-x86-64In der AWS-Konsole:
adaptix-deployerAmazonDynamoDBFullAccessAWSLambda_FullAccessIAMFullAccessCloudWatchLogsFullAccess{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"kms:*","Resource":"*"}]}KMSFullAccessaws configure
# AWS Access Key ID: <paste access key>
# AWS Secret Access Key: <paste secret key>
# Default region: us-east-1
# Default output format: json
Überprüfen:
aws sts get-caller-identity
# Build the Lambda relay binary (cross-compiled for Amazon Linux)
./scripts/build_relay.sh
# Deploy Lambda + DynamoDB + IAM with Terraform
./scripts/deploy_infra.sh
# Note the Lambda Function URL from the output, e.g.:
# lambda_function_url = "https://xxxxx.lambda-url.us-east-1.on.aws"
./scripts/install.sh /path/to/AdaptixC2
Dieses Skript wird:
dist/-Verzeichnis sichern (Zertifikate, Datenbank, Profil)GOEXPERIMENT-Flags aus dem Server-Binary erkennen.so) mit passenden Flags bauenBeaconServerless-Listenerrelay_api_key in Ihrer terraform.tfvars übereinstimmen)profiles/lambda_default.json hochBeaconServerless-Listenerdeploy/aws/terraform.tfvars)region = "us-east-1"
function_name = "adaptix-relay"
relay_api_key = "your-secret-key-here"
tags = {
Project = "adaptix-serverless"
}
| Feld | Beschreibung | Standard |
|---|---|---|
| AWS Region | Region, in der die Infrastruktur bereitgestellt wird | us-east-1 |
| Lambda URL | Function URL aus der Terraform-Ausgabe | (erforderlich) |
| Relay API Key | Muss mit dem relay_api_key von Terraform übereinstimmen | (optional) |
| Inbound Table | DynamoDB-Tabelle für Agent-Check-ins | adaptix-inbound |
| Outbound Table | DynamoDB-Tabelle für Server-Antworten | adaptix-outbound |
| Poll Interval | Wie oft DynamoDB abgefragt wird (Sekunden) | 5 |
| TTL Hours | Ablauf von DynamoDB-Datensätzen | 24 |
Der Kharon-Agent verwendet ein benutzerdefiniertes Binärprotokoll über HTTP:
[36-byte UUID][encrypted_checkin_data][16-byte LokyCrypt key][36-byte UUID][encrypted_payload] (kein nachfolgender Schlüssel)TotalLen-16 in den UUID-Bereich. Bei einem 44-Byte-Paket beginnt der Schlüssel bei Offset 28 und überschreibt die UUID-Bytes 28-35 sowie alle verschlüsselten Daten.Der Listener erkennt alle drei Formate und behandelt sie korrekt.