
BL00DYM4RY
Educational trojan simulator for cybersecurity training, simulating phishing attacks with social engineering, system reconnaissance, anti-sandbox…

Educational trojan simulator for cybersecurity training, simulating phishing attacks with social engineering, system reconnaissance, anti-sandbox…

Modular phishing framework with CLI for cloning sites, sending templated emails, and launching phishing campaigns via email, SMS, iMessage, and…

Automates phishing and post-phishing activities with an almost-transparent reverse proxy that dynamically mirrors target web apps and interacts with…

Red team ransomware simulator with custom payload generation, centralized C2 dashboard, and file encryption/decryption for penetration testing.

Phishing page source code mimicking official Flash Player download site (flash.cn) to trick users into downloading malicious payload. Supports…

Automated WPA attack tool that captures handshakes, deploys a fake access point with captive portal, and phishes credentials via social engineering…

A lightweight, self-hosted simulation tool for "ClickFix" (ClearFake) social engineering training. Safely simulates clipboard-injection attacks with…

Automated Facebook account security testing tool using Selenium and Mechanize for credential harvesting, graph analysis, and social engineering…

Automated man-in-the-middle attack tool.

An automated Wireless RogueAP MITM attack framework.

Bash script for Evil Twin attack automation: scans Wi-Fi networks, captures handshakes, deploys a fake AP with DHCP/DNS, and serves phishing…

Remote Administration Tool for Android devices

A tool to transform Chromium browsers into a C2 Implant

OTP BOT Bypass SMS verifications from Paypal, Instagram, Snapchat, Google, 3D Secure, and many others...

CVE-2024-3094 XZ Utils backdoor research - attack surface visualiser, system vulnerability checker, and general Linux CVE assessment tool

Windows tool that disguises executable files by spoofing their icons and extensions using Unicode RLO characters, making .exe, .scr, and .com files…

(DOM-based XSS) HTML Injection vulnerability in TOWeb v.12.05 and before allows an attacker to inject HTML/JS code via the _message.html component.

OSINT tool for automated scanning of social networks and other websites, using a single nickname.