
malvinci
This simple but powerful script will introduce a new type of malware that will turn off the firewall, start an HTTP server, forward its port through…

This simple but powerful script will introduce a new type of malware that will turn off the firewall, start an HTTP server, forward its port through…

A project created with an aim to emulate and test exfiltration of data over different network protocols.

C# tool for exfiltrating files over DNS using XOR and asymmetric encryption, designed for red team engagements with restricted outbound connections.

In-depth reverse engineering analysis of Lumma Stealer, an info-stealer using process hollowing, Native API calls, and C2 communication. Includes…

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

Bypassing EDR's with stealthy c++ telegram Bot and Telegram itself as C2 interface !

A C2 framework for initial access in Go

An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

Exfiltrate blind Remote Code Execution and SQL injection output over DNS via Burp Collaborator.

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Windows keylogging module for the Sliver C2 implant framework, using Raw Input to capture keystrokes and expose start, stop, and retrieval commands…

Youtube as C2 channel - Control Windows systems uploading QR videos to Youtube

Full-spectrum Linux adversary simulation platform with kernel-level stealth, C2 beaconing, privilege escalation, credential harvesting, lateral…

WORK IN PROGRESS. RAT written in C++ using Win32 API

Reverse engineering analysis of AcrStealer, a sophisticated info-stealer that uses custom protocols, browser credential theft, and payload…

Source code minh họa máy chủ c2 demo kịch bản thực thi của CVE-2024-23700

Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves unauthenticated remote code…