
ImgBackdoor
Builds a trojanized .jpg.exe agent that downloads and executes a user-supplied PowerShell, Batch, or Metasploit payload, then opens a Meterpreter…

Builds a trojanized .jpg.exe agent that downloads and executes a user-supplied PowerShell, Batch, or Metasploit payload, then opens a Meterpreter…

Red team ransomware simulator with custom payload generation, centralized C2 dashboard, and file encryption/decryption for penetration testing.

Generate obfuscated Excel 4.0 XLM macros for red team operations and blue team analysis, with support for multiple infection techniques, formula…

Encodes binary implants into HTML files for phishing delivery, decoding and dropping the payload when the target opens the file. Supports custom…

Use a Fake image.jpg to exploit targets (hide known file extensions)

A tool to transform Chromium browsers into a C2 Implant

Encrypts and embeds any file into an HTML page with automatic decryption and download simulation for social engineering and payload delivery.

Scripts for generating Office macro payloads to deliver executables and PowerShell commands, aiding in red team engagements and phishing simulations.

C-based XLL payload development for phishing campaigns, with techniques for delivery via ZIP containers, self-deletion, and evasion of AV/EDR and…

Inject DLLs into the explorer process using icons

Social engineering toolkit for bulk phishing campaigns with macro-based payload generation, email tracking, and automated agent deployment for…

Generate C2 payloads embedded in favicon files, executed via PowerShell for covert command-and-control operations.

Automated framework for CVE-2023-38831 exploitation with payload generation, email delivery, and download link creation for social engineering…

This is a Automated Generate Payload for CVE-2019-11932 (WhatsApp Remote Code Execution)

PoC exploit for CVE-2023-52076 - zip-slip path traversal in Atril/Xreader (MATE/Cinnamon) enabling arbitrary file write and RCE via crafted EPUB.…

PoC exploit chain for WordPress pre-auth XSS to RCE via DOM clobbering, REST JSONP/SOME, and plugin upload, with Docker lab verification and…

Proof-of-concept exploit for CVE-2025-1015 demonstrating unsanitized URI fields in Thunderbird Address Book leading to unprivileged JavaScript…