
AI-FILE
A listener profile for the Mythic C2 framework that utilizes AI vendors file API's

A listener profile for the Mythic C2 framework that utilizes AI vendors file API's

Reverse engineering analysis of StealC Stealer, an info-stealer that uses RuntimeBroker.exe hollowing, C2 infrastructure, and payload extraction.…

Reverse engineering analysis of AcrStealer, a sophisticated info-stealer that uses custom protocols, browser credential theft, and payload…

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.

Hooked browser communication over MQTT

"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory…

Python backdoor that uses http post/get requests to communicate

A fully featured Windows backdoor that uses email as a C&C server

SQLC2 is a PowerShell script for deploying and managing a command and control system that uses SQL Server as both the control server and the agent.

🐐 GoAT (Golang Advanced Trojan) is a trojan that uses Twitter as a C&C server

A Simple Python Program that uses gets a Remote Root Shell on the Target Device by exploiting a Vulnerability (CVE-2011-2523) present in vsFTP 2.3.4

Rig Exploit for CVE-2018-8174 As with its previous campaigns, Rig’s Seamless campaign uses malvertising. In this case, the malvertisements have a…

CVE 2021-44228 Proof-of-Concept. Log4Shell is an attack against Servers that uses vulnerable versions of Log4J.

Detects phi-structured C2 beacons that evade RITA and standard regularity-based detectors

An exploit for vulnerable versions of fontforge and setuptools plus a practical example.

F5 BIG-IP Exploit Using CVE-2022-1388 and CVE-2022-41800