
SpotifyC2
Windows-based C2 research tool that uses Spotify playlists as a command channel and Telegram for output delivery, demonstrating cloud-assisted…

Windows-based C2 research tool that uses Spotify playlists as a command channel and Telegram for output delivery, demonstrating cloud-assisted…

Proof-of-concept exploit for CVE-2025-27590, a command injection vulnerability in multipart form uploads enabling remote shell execution and SSH key…

Cross Platform Telegram based RAT that communicates via telegram to evade network restrictions

Detailed disclosure of CVE-2025-67511, a command injection vulnerability in the CAI framework's SSH tool that allows AI agents to be tricked into…


A fully featured Windows backdoor that uses Gmail as a C&C server

Azure Function that validates and relays Cobalt Strike beacon traffic using malleable C2 profiles, redirecting invalid requests to a decoy site and…

Python / C# Unmanaged PowerShell based RAT

Blaze Telegram Backdoor Toolkit is a post-exploitation tool that leverages the infrastructure of Telegram as a C&C

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Transparent proxy server that works as a poor man's VPN. Forwards over ssh. Doesn't require admin. Works with Linux and MacOS. Supports DNS…

Apache Solr instances that may be affected by CVE-2026-44825, related to Velocity Template Remote Code Execution (RCE) conditions.

This exploit is based on CVE-2023-6553 and was built upon the original exploit by Chocapik, it was added that a direct reverse shell can be obtained.

Open source pre-operation C2 server based on python and powershell

Revenant - A 3rd party agent for Havoc that demonstrates evasion techniques in the context of a C2 framework

This is a PowerShell based tool that is designed to act like a RAT. Its interface is that of a shell where any command that is supported is…

A fully featured backdoor that uses Twitter as a C&C server

CVE-2025-32433 Erlang/OTP SSH RCE Exploit SSH远程代码执行漏洞EXP