
Rusty-Playground
Some Rust program I wrote while learning Malware Development

Some Rust program I wrote while learning Malware Development

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

ASPX web shell with COFF loader for executing Beacon Object Files (BOFs) on target servers via a semi-interactive Python client, designed for…

CVE-2020-8012, CVE-2016-10709, CVE-2017-17099, CVE-2017-18047, CVE-2019-1003000, CVE-2018-1999002

Evades AV and sandboxes on Windows using anti-sandbox checks, ntdll unhooking, dynamic API resolution, and multi-layer shellcode obfuscation…

ImaegMagick Code Execution (CVE-2016-3714)

NØW is a word-based shellcode encoding and obfuscation tool that transforms raw shellcode bytes into natural-looking English prose.


Indirect syscalls + DInvoke made simple.

Automated deployment tool for CVE-2024-31317 PoC on Android 9-13, enabling privilege escalation via Zygote injection and reverse shell execution.

ShellcodeFluctuation PoC ported to Nim

Remote Code Execution via Use-After-Free in JScript.dll (CVE-2025-30397)

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Stealthy .NET assembly loading using AssemblyNative::LoadFromBuffer

Python-based exploit for CVE-2021-21086 in Adobe Acrobat Reader DC, generating malicious PDFs with shellcode execution via crafted font charstrings.

WAMpage - A WebOS root LPE exploit chain (CVE-2022-23731)

WORK IN PROGRESS. RAT written in C++ using Win32 API

Proof-of-concept exploit for CVE-2025-29824, a use-after-free vulnerability in the Windows CLFS kernel driver, demonstrating privilege escalation to…