tisdag 7 december 2021

Divide RAT can now fast-flux.

 


My divide RAT - Suite can now point a domain on hjiacked machine on check in to c2 and point the domain to it self so i can use hacked machines as proxys. ...


Hacker --> VPN --> TOR --> Hacked Computer --> Target

and it support all protocols so you can use like sqlmap or rdesktop to connect to the target. 

so the domain points to every hacked machine that checks in so it keep chaning all the time

so work like fast-flux like system ... 


måndag 22 november 2021

Store Malware In The Graphic Card

 



POC . the dropper exec the opencl code into the gpu kernel.

and then it read out the result into CPU and injects it into RAM (DLL) (remote process)

then it unloads it self and the reinject the payload evry 10sec so the payload is just inejcted few seconds 

TADA! a ghost in the GPU ...

onsdag 13 oktober 2021

Windows 11 Kernel Rootkit (M4A1 Glitch Kit)


 


injects into any browser even if process blocking 3rd unsigned dlls. ...
in this pic you can see it injected cobal strike into top popular process ...


and it keep hiden from tools/users ....


fredag 27 augusti 2021

Bitcoin As Botnet Server (enslaved blockchain)

 


Hi was able to crawl blockchain tx and get result of the data text (op_return) tx 

and use it to distribute c2 commands to my bots(slaves) to control botnets

with this you dont need a c2 server and can stay 100% anonymous 



for more info pleas contact me at claes.spett@gmail.com 

fredag 2 juli 2021

Pidgin from bug to 0day? (0Day)


 

access violation .... lets see if its possible to exploit , i will update the blog asap when i know ... BRB

pleas contact me at claes.spett@gmail.com for more info!

onsdag 30 juni 2021

Flame. V 3 (Kernel Driver) / Ring0 - Rootkit


Now have a RING0 hidden driver and injects its x64 dll payload into running process to talk back to the c2 using APC to talk back to RING3, ..

söndag 21 februari 2021

Screenmirrior using RC4

 




my SCADA RAT now have support for screen mirroring (mirror the infected machine)

it using rc4 encryption commutation.

right now i will work on mouse control , so stay tuned! 

måndag 11 januari 2021

SCADA Killer RAT

 



My SCADA killer rat can now wipe over SCADA configure file and flood the PLC after the attacker reconfigure the plc via reverse desktop in the hmi system


and show the operator everything run as normal 



OLD DEMO ---> https://www.youtube.com/watch?v=EcpdlEKkegY&t=5s&ab_channel=Claes