
malvinci
This simple but powerful script will introduce a new type of malware that will turn off the firewall, start an HTTP server, forward its port through…

This simple but powerful script will introduce a new type of malware that will turn off the firewall, start an HTTP server, forward its port through…

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain

Investigation of CVE-2024-4577 exploitation and AsyncRAT deployment with DFIR artifacts, IoCs, and detection guidance.

An example of a remote administration tool.

Telegram Desktop Session Stealer

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

SubSeven Legacy Official Source Code Repository

Venom is a library that meant to perform evasive communication using stolen browser socket

TeleShadow - Telegram Desktop Session Stealer (Windows)

Self-healing RAT utilizing libp2p

WORK IN PROGRESS. RAT written in C++ using Win32 API

Proof-of-concept exploit for CVE-2026-33725, achieving remote code execution and arbitrary file read via H2 JDBC INIT injection in Metabase…

Claude Code Remote Code Execution

Double-free vulnerability in DDGifSlurp in decoding.c in libpl_droidsonroids_gif can read more…

Automated proof-of-concept exploit for CVE-2021-44521, enabling remote code execution on Apache Cassandra via user-defined functions. Executes…