
BloodfangC2
Modern PIC implant for Windows (64 & 32 bit)

Modern PIC implant for Windows (64 & 32 bit)

Nim library for dynamically invoking Windows API functions via PEB walks to avoid static imports and EDR hooking, enabling stealthier implants and…

Encrypts .NET executables with a polymorphic stub, junk-code flooding, and entry-point proxy to protect malware payloads from static detection.

A payload delivery system which embeds payloads in an executable's icon file!

Nim PoC that hooks Sleep to encrypt in-memory shellcode during idle periods, defeating memory scanner detection and supporting C2 implant operations.

Curated proof-of-concept implementations of malware TTPs, covering persistence, privilege escalation, command-and-control, and post-exploitation for…

A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go

PoC demonstrating quadratic DoS in Elixir html_sanitize_ex via crafted HTML; includes timing benchmarks, remote exploitation curl, and verification…

Proof-of-concept exploiting WordPress pre-auth XSS to RCE via DOM clobbering, REST API abuse, and malicious plugin upload for server-side execution.…

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

Threadless Process Injection using remote function hooking.