Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ICMP-Ghost-A-Fileless-x64-Assembly-C2-Agent — Fileless x64 Assembly C2 framework with dual-channel ICMP/DNS protocol pivoting, direct syscall execution, and ptrace-based process injection for stealthy command execution and data exfiltration. | Kitploit
Tools/GitHubGitHub/jm00nj/icmp-ghost-a-fileless-x64-assembly-c2-agent
Privilege EscalationExploit FrameworksIDS/IPS EvasionShellcodePost-ExploitationCommand and ControlRed TeamingPayload Development

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
jm00nj/icmp-ghost-a-fileless-x64-assembly-c2-agent

ICMP-Ghost-A-Fileless-x64-Assembly-C2-Agent

Fileless x64 Assembly C2 framework with dual-channel ICMP/DNS protocol pivoting, direct syscall execution, and ptrace-based process injection for stealthy command execution and data exfiltration.

View RepositoryWebsite
8818161 month agoReviewed by Kitploit
 ________  ___  ___  ________  ________  _________       ________  ________   
|\   ____\|\  \|\  \|\   __  \|\   ____\|\___   ___\    |\   ____\|\_____  \  
\ \  \___| \ \  \\\  \ \  \|\  \ \  \___|\|___ \  \_|    \ \  \___|\|____|\  \ 
 \ \  \  __ \ \   __  \ \  \\\  \ \_____  \   \ \  \      \ \  \     ____\_\  \
  \ \  \|\  \ \  \ \  \ \  \\\  \|____|\  \   \ \  \      \ \  \___|\____ \  \
   \ \_______\ \__\ \__\ \_______\____\_\  \   \ \__\      \ \______\\_________\
    \|_______|\|__|\|__|\|_______|\_________\   \|__|       \|______\|_________|
                                 \|_________|                                   

Fileless, pure x64 Assembly C2 implant utilizing a Dual-Channel (ICMP / DNS) architecture. Zero libc. Zero disk. Invisible to standard EDR hooks.


Architecture Language Protocol Protocol OS Version Suricata GitHub stars GitHub license GitHub repo size

Ghost-C2

Overview

⭐️ If you find this research useful, please consider giving it a star to support further development

🚨 FULL TECHNICAL RESEARCH & SOURCE CODE: This repository is a summary. For the complete architectural breakdown, W^X memory evasion details, and VTable implementation, visit the official project page: ICMP-Ghost Technical Breakdown

Ghost-C2 is a command-and-control framework written entirely in pure x64 Linux Assembly with no libc dependencies. Every operation goes through direct syscalls. There are no import tables, no dynamic linker artifacts, and no disk writes.

Originally built as a raw ICMP stealth channel, version 3.6.2 introduces a Dual-Channel Protocol Pivoting architecture. Operators can seamlessly switch the implant's communication channel between silent ICMP Raw Sockets and evasive DNS UDP Tunneling on the fly. The implant lives exclusively in RAM, injected into a running system process via a custom ptrace-based loader.

This project was built to explore how far user-space stealth and network state synchronization can go without touching the kernel.


Architecture

ghost-c2-architecture
┌─────────────────────────────────────────────────────────────┐
│                      OPERATOR MACHINE                       │
│                                                             │
│   ┌──────────────┐                                          │
│   │  client.asm  │  ← Terminal UI: Prompt IP/Domain + Cmd   │
│   │  (Operator   │    Encrypts payload with Rolling XOR     │
│   │   Console)   │    State Sync: ICMP mode / DNS mode      │
│   └──────┬───────┘                                          │
│          │                                                  │
└──────────┼──────────────────────────────────────────────────┘
           │  Channel 1: Raw ICMP (Stateless, Port-less)
           │  Channel 2: DNS UDP Port 53 (Asymmetric)
┌──────────┼──────────────────────────────────────────────────┐
│          │             TARGET MACHINE                       │
│          ▼                                                  │
│   ┌──────────────┐     ┌─────────────────────────────────┐  │
│   │  loader.asm  │────▶│         sniff.asm (PIC)         │  │
│   │  (Phantom    │     │         Lives in RAM only       │  │
│   │   Loader)    │     │         inside host process     │  │
│   └──────────────┘     └────────────────┬────────────────┘  │
│                                         │                   │
│   1. Scans /proc for target PID         │ Listens ICMP/DNS  │
│   2. ptrace ATTACH                      │ Validates Auth    │
│   3. Force remote mmap (RW)             │ Decrypts command  │
│   4. Inject PIC shellcode               │ fork+execve       │
│   5. mprotect → RX                      │ memfd_create      │
│   6. Redirect RIP → shellcode           │ Compress(DPCM-RLE)│
│   7. ptrace DETACH → exits              │ Encrypt & Frag.   │
│                                         │ Sends Reply       │
└─────────────────────────────────────────┼───────────────────┘
                                          │  Encrypted Traffic
                                          ▼
                                   [ client.asm ]
                                   Receives & Validates
                                   Decrypts Payload
                                   Decompresses (Hybrid)
                                   Reassembles & Prints

Components

client.asm — Operator Console

The attacker-side terminal. Handles UI, dynamic memory management, and target state synchronization. Can dispatch packets as either ICMP Echo Requests or DNS TXT queries. Listens for fragmented replies, prevents buffer overflows, and reconstructs the output. Features an "Active Target Reconnection" module to rescue orphaned sessions.

sniff.asm — PIC Implant Agent

The implant running on the target. Compiled as a raw binary (position-independent, no ELF headers) so it can be injected into arbitrary memory addresses. It dynamically updates its internal VTable to switch between ICMP sniffing and UDP DNS binding based on operator pivot commands.

Phantom_Loader/loader.asm — Injection Engine

The delivery mechanism. Scans /proc, finds a target process by comm name, and injects the PIC shellcode into it using a multi-stage ptrace state machine. Exits cleanly after injection — leaves no trace.


Stealth & Evasion Techniques

Dual-Channel Protocol Pivoting (ICMP ↔ DNS)

Ghost-C2 v3.6.2 allows the operator to hot-swap the network protocol without losing the agent. By sending specific pivot commands, the VTables in both the Master and the Agent are dynamically overwritten:

  • !D (Pivot to DNS): Both nodes close ICMP sockets and initialize UDP Port 53 communication. Ideal for bypassing strict Layer 3 filtering by blending into corporate DNS traffic.
  • !I (Pivot to ICMP): The Agent closes UDP sockets, kills port bindings, and drops back into silent Raw Socket sniffing. Perfect for "Phantom" stealth mode.

DPCM-RLE Hybrid x64 Compressor

Ghost-C2's data transmission engine utilizes a hybrid compression and encoding layer heavily optimized in x86-64 Assembly.

  • DPCM (Differential Pulse Code Modulation): Calculates and sends the mathematical difference (Delta) between a reference character and subsequent ones, lowering data entropy.
  • RLE (Run-Length Encoding): Packs consecutive spaces and repeating blocks at the bit level.
  • Result: Reduces overall data payload by 40% to 55%, minimizing network footprint and the number of injected packets.

ICMP Protocol Mimicry

Every outgoing ICMP packet is structured to be indistinguishable from a standard Linux ping:

  • Dynamic RDTSC timestamps mimic struct timeval.
  • Exact Linux iputils padding (0x10 to 0x1F) bypasses basic heuristic firewalls.
Download Tool