
GPU_ShellCode
Hides reflective payloads in GPU memory via CUDA APIs, wiping host memory during sleep and using a VEH handler to restore executable memory, evading…

Hides reflective payloads in GPU memory via CUDA APIs, wiping host memory during sleep and using a VEH handler to restore executable memory, evading…

macOS Initial Access Payload Generator

Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post

A new simple and powerfull packer for malware

A payload delivery system which embeds payloads in an executable's icon file!

PoC MSI payload based on ASEC/AhnLab's blog post

Threadless Process Injection using remote function hooking.

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

Dynamically invoke arbitrary unmanaged code from managed code without PInvoke.

C# obfuscator that bypass windows defender

Weaponize DLL hijacking easily. Backdoor any function in any DLL.

Inject DLLs into the explorer process using icons

A delicious, but malicious SSL-VPN server 🌮

Encypting the Heap while sleeping by hooking and modifying Sleep with our own sleep that encrypts the heap

A simple ptrace-less shared library injector for x64 Linux

PE obfuscator with Evasion in mind

Lockbit3.0 Microsoft Defender MpClient.dll DLL Hijacking PoC