
Mythic
A collaborative, multi-platform, red teaming framework

A collaborative, multi-platform, red teaming framework

Android remote administration tool

Self-contained Python PoC exploiting the MikroTrick SSH chain (CVE-2026-86060, CVE-2026-67279) to gain unauthenticated full admin access on MikroTik…

Stealth Kid RAT (SKR) is an open-source multi-platform Remote Access Trojan (RAT) written in C#. Released under MIT license. The SKR project is fully…

RAT-el is an open source penetration test tool that allows you to take control of a windows machine. It works on the client-server model, the server…

Automated proof-of-concept exploit for CVE-2021-44521, enabling remote code execution on Apache Cassandra via user-defined functions. Executes…

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

DarkAgent Remote Administration Tool RAT by DragonHunter

Proof-of-concept exploit for CVE-2019-2107, demonstrating remote code execution via crafted HEVC video on Android media framework. Includes crash…

Unauthenticated remote code execution exploit for PowerJob Server via Groovy injection in the /friend/process endpoint, enabling arbitrary command…

Android Remote Access Trojan

Self-healing RAT utilizing libp2p

Proof-of-concept exploit for CVE-2026-1731, a blind RCE in BeyondTrust Privileged Remote Access and Remote Support, allowing remote command execution…

C# remote access trojan (RAT) implant for the Caldera adversary emulation framework, enabling post-exploitation command and control on Windows…

Uses Shodan API to pull down C2 servers to run known exploits on them.

Python framework exploiting CVE-2026-46339 for unauthenticated RCE on 9Router via MCP bridge, using temporal sharding and dispersion to evade…

👁️ (s)AINT is a Spyware Generator for Windows systems written in Java. [Discontinued]

Damn easy multiplatform Node.js RAT generator.