
ghost
Lightweight RAT providing silent remote command-line access, hidden file download/execution, and persistence mechanisms for Windows systems.…

Lightweight RAT providing silent remote command-line access, hidden file download/execution, and persistence mechanisms for Windows systems.…

Telegram Desktop Session Stealer

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

TeleShadow - Telegram Desktop Session Stealer (Windows)

A list of useful Powershell scripts with 100% AV bypass (At the time of publication).

Double-free vulnerability in DDGifSlurp in decoding.c in libpl_droidsonroids_gif can read more…

POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution

Python based backdoor that uses Gmail to exfiltrate data through attachment. This RAT will help during red team engagements to backdoor any Windows…

xll windows reverse shell

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Self-healing RAT utilizing libp2p

Python framework exploiting CVE-2026-46339 for unauthenticated RCE on 9Router via MCP bridge, using temporal sharding and dispersion to evade…

DarkAgent Remote Administration Tool RAT by DragonHunter

Android remote administration tool

A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.

CVE-2025-62593 — Ray Unauthenticated RCE Exploit is an unauthenticated remote code execution vulnerability in the Ray distributed AI compute engine.

SpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code Execution

Unauthenticated remote code execution exploit for PowerJob Server via Groovy injection in the /friend/process endpoint, enabling arbitrary command…