
JS-Tap
JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

🐾Dogwalk PoC (using diagcab file to obtain RCE on windows)

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks

An evil RAT (Remote Administration Tool) for macOS / OS X.

A tool to abuse Exchange services

Generate Gmail Emailing Keyloggers to Windows.

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

This repo covers some code execution and AV Evasion methods for Macros in Office documents

Remote operations commands implemented using Beacon Object Files

A tool to transform Chromium browsers into a C2 Implant

This is a repository of resource about Malware techniques

🐐 GoAT (Golang Advanced Trojan) is a trojan that uses Twitter as a C&C server

Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS. 🍎💻

Generate Payloads and Control Remote Machines. [Discontinued]

macOS Initial Access Payload Generator

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

Loki.Rat is a fork of the Ares RAT, it integrates new modules, like recording , lockscreen , and locate options. Loki.Rat is a Python Remote Access…