
slot2
UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

CVE-2025-8088 exploitation chain + Quasar C2 multi-stage payload delivery

A list of useful Powershell scripts with 100% AV bypass (At the time of publication).

CVE-2026-38426 — strcpy() Stack Buffer Overflow in Tasmota fetch_jpg() boundary[40] (Tasmota <= 15.3.0.3)

An open-source, C#-based remote administration tool (RAT), enabling complete control of a remote Windows machine, designed for legitimate remote…

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain

Malicious PixelCode is a security research project that demonstrates a covert technique for encoding executable files into pixel data and storing…

Android remote administration tool

This is a webshell open source project

Python Remote Administration Tool (RAT) to gain meterpreter session

Remote Access Trojan (RAT) for Windows x64 using a combination of vulnerability CVE-2023-38831 (WinRAR < 6.23 vulnerability) and Shellcode…

Venom is a library that meant to perform evasive communication using stolen browser socket

DNS over HTTPS targeted malware (only runs once)


A simple remote tool in C#.

A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.

Stealth Kid RAT (SKR) is an open-source multi-platform Remote Access Trojan (RAT) written in C#. Released under MIT license. The SKR project is fully…