Mythic C2 프레임워크를 위한 리스너 프로필로, AI 벤더의 파일 API를 활용합니다
ai_file은 공개적으로 문서화된 OpenAI Files API를 사용하여 기존의 HTTP/S 리스너 대신 jsonl 파일을 통해 임플란트 메시지를 교환하는 Mythic C2 프로파일입니다. 이는 OpenAI가 공개 문서에서 정의한 Files API 동작에 의존합니다: https://developers.openai.com/api/docs/guides/file-inputs?api-mode=responses.
리스너는 /v1/files 엔드포인트를 폴링하여 purpose=batch인 .jsonl 파일을 찾고, 각 요청 봉투를 로컬에서 복호화한 후, 원시 Mythic 메시지 바이트를 Mythic의 /agent_message로 전달하고, Mythic의 응답을 암호화한 다음, 응답 .jsonl 파일을 Files API에 다시 업로드합니다.
\
Mythic 디렉터리에서:
sudo ./mythic-cli install folder /path/to/openai_file
sudo ./mythic-cli c2 start openai_file
프로파일을 시작하기 전에 C2_Profiles/openai_file/openai_file/c2_code/config.json을 편집하십시오:
{
"instances": [
{
"name": "default",
"api_key": "REPLACE_ME",
"base_url": "https://api.openai.com/v1",
"organization": "",
"project": "",
"purpose": "batch",
"channel_id": "mythic",
"request_prefix": "mythic_to_server",
"response_prefix": "mythic_to_agent",
"transport_key": "REPLACE_ME",
"poll_interval_seconds": 5,
"delete_processed_files": true,
"debug": true,
"max_file_bytes": 10485760,
"mythic_host": "",
"mythic_port": 0
}
]
}
필수 값은 api_key, transport_key, 그리고 리스너와 페이로드 프로파일 구성 간에 일치하는 channel_id입니다. transport_key는 base64:<32 raw bytes> 또는 높은 엔트로피의 패스프레이즈일 수 있습니다; 패스프레이즈는 봉투 암호화 사용 전에 SHA-256으로 파생됩니다.
에이전트와 리스너는 purpose=batch를 사용하여 OpenAI의 Files API .jsonl 파일을 통해 파일을 교환합니다.
요청 파일 이름:
<request_prefix>_<channel_id>_<request_id>.jsonl
응답 파일 이름:
<response_prefix>_<channel_id>_<request_id>.jsonl
기본 요청 접두사는 mythic_to_server입니다; 기본 응답 접두사는 mythic_to_agent입니다; 기본 채널은 mythic입니다.
각 파일은 한 줄에 하나씩, 하나 이상의 JSON 객체를 포함합니다:
{"v":1,"profile":"openai_file","channel":"mythic","direction":"request","id":"req_001","alg":"aes-256-cbc-hmac-sha256+base64url","nonce":"...","ciphertext":"...","created_at":0}
ciphertext는 원시 Mythic 메시지 바이트에 대한 후행 HMAC-SHA256 태그가 있는 AES-256-CBC 출력입니다. nonce는 CBC IV입니다. nonce와 ciphertext는 패딩 없는 base64url입니다. AAD는 다음과 같습니다:
v|profile|channel|direction|id|alg
예를 들어:
1|openai_file|mythic|request|req_001|aes-256-cbc-hmac-sha256+base64url