Blog

Latest Posts

· Krait Team · 7 min read

Cloud Post-Exploitation from a Compromised Host: 48 BOFs for AWS, Azure, GCP, and Kubernetes

Why cloud post-exploitation belongs in the C2, not in a separate toolkit — and how Krait's cloud BOFs turn a compromised workstation into a cloud pivot point.

· Krait Team · 7 min read

Building a macOS Implant: What Works, What Doesn't, and What Apple Breaks on Purpose

The design decisions behind Krait's macOS agent — why we chose SecureTransport over OpenSSL, how DYLD spawning works with SIP, and the IOKit trick that keeps WiFi alive.

· Krait Team · 7 min read

Traffic Blending with CDN Redirectors: Hiding C2 in Legitimate Cloud Infrastructure

How Krait uses CloudFront and Azure Front Door to route C2 traffic through cloud provider infrastructure — valid TLS certificates, cloud IP ranges, and zero C2 server exposure.

· Krait Team · 6 min read

Polymorphic by Default: Why Static Signatures Can't Fingerprint Krait

How Krait's build system randomizes every binary across multiple independent axes, making a signature from one captured sample match exactly one sample.

· Krait Team · 8 min read

Disappearing Into SaaS Traffic: Krait's Malleable Communication Profiles

How Krait shapes C2 traffic to mimic legitimate SaaS API patterns — matching URIs, headers, body formats, and even the binary's identity to a specific application.

· Krait Team · 6 min read

Building a C2 on Raw Sockets: Why Krait Doesn't Use WinHTTP

Why Krait uses raw Winsock and Schannel instead of WinHTTP or WinINet, and how buffer ownership makes sleep encryption actually work.

· Krait Team · 7 min read

Tampered Syscalls: Executing from ntdll Without Writing a Single Stub

How Krait uses hardware breakpoints and a decoy Nt function to make every syscall execute from ntdll's own code — no allocated stubs, no suspicious return addresses.

· Krait Team · 6 min read

The Sleep Encryption Triad: Zero Cleartext in Memory

How Krait coordinates three encryption layers — code, data, and heap — to leave nothing recoverable during sleep intervals.

· Krait Team · 6 min read

PE Fluctuation: Demand-Paged Encryption for Always-On Protection

Why encrypting only during sleep isn't enough, and how Krait uses VEH-based demand paging to keep code encrypted even between polls.

· Krait Team · 5 min read

Introducing Krait: Evasion-First Command & Control

Why we built Krait, what makes it different from Cobalt Strike and Brute Ratel, and where we're headed.