
Venom
Venom is a library that meant to perform evasive communication using stolen browser socket

Venom is a library that meant to perform evasive communication using stolen browser socket

Post Exploitation agent which uses a browser to do C2 operations.

Filesystem interaction via firebeam virtual machine execution

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

Hooked browser communication over MQTT

Proof-of-concept exploit for CVE-2026-54088, a pre-authentication OS command injection in File Browser <=2.63.5. Demonstrates shell injection via…

A tool to transform Chromium browsers into a C2 Implant

The Browser Exploitation Framework Project

XSScope is one of the most powerful and advanced GUI Framework for Modern Browser exploitation via XSS.

Manual, non-Metasploit authenticated Remote Code Execution (RCE) exploit via the browser URL bar for Webmin 1.580 (CVE-2012-2982)

Browser-based CVE-2021-21220 exploit delivering a reverse shell via shellcode and a C2 implant for remote command execution on Windows targets.