Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
tor-rootkit — A Python 3 standalone Windows 10 / Linux Rootkit using Tor. | Kitploit
Tools/GitHubGitHub/emcruise/tor-rootkit
Payload GenerationPenetration TestingCommand and ControlLearning & EducationRed TeamingRemote Access Tool
GitHubemcruise/tor-rootkit

tor-rootkit

A Python 3 standalone Windows 10 / Linux Rootkit using Tor.

View Repository
1822853 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

tor-rootkit

Docker build test Windows & Linux executables

A Python 3 standalone Windows 10 / Linux Rootkit. The networking communication get's established over the tor network.

This rootkit is WIP.

Disclaimer

Use for educational purposes only.

How to use

  1. Clone the repo and change directory:
root@kitploit:~
git clone https://github.com/emcruise/tor-rootkit.git
cd ./tor-rootkit
  1. Build docker container:
root@kitploit:~
docker build -t listener .
  1. Run docker container:
root@kitploit:~
docker run -v $(pwd)/executables:/executables/ -it listener
  1. Deploy the executables: When the listener is up and running it generates a "executables" directory containing different payloads for different plattforms.
Download Tool
root@kitploit:~
tor-rootkit/
│    ...
└    executables/

Note: The client can take some time to connect because PyInstaller executables are a bit slower and it need's to start tor.

Features

  • Standalone executables for Windows and Linux, including python interpreter and tor
  • the whole communication works over tor hidden services which guarantees some degree of anonymity
  • The Listener can handle multiple clients
  • The Listener generates payloads for different platforms on startup

Listener Shell Commands

CommandExplanation
helpShows the help menu
^C or exitExits the shell
listlists all connected clients with their according index
select <index>start shell with client

Client Shell Commands

CommandExplanation
helpShows the help menu
^C or exitExits the client shell and returns to listener shell
os <command>Executes a command in the clients shell and returns the output
backgroundKeeps the connection to a client and returns to listener

Contribution

Any contributions are appreciated. Make a pull-requests and I'll merge if it passes my automatic tests.