Changelog

Release History

v3.0.0 September 28, 2026

macOS Agent, Cloud BOFs, CDN Redirectors

macOS Agent

  • macOS implant shipped — Universal binary (arm64 + x86_64) with SecureTransport TLS, DNS, and DOH transports. Same wire protocol as Windows and Linux — server handles all three transparently
  • 91 macOS BOFs — shared Linux BOFs minus 16 Linux-only ones (cgroup_escape, nsenter_host, persist_systemd, etc.). macOS-specific overrides for persist-cron (handles “no crontab” error) and persist-bashrc (targets .zshrc/.zprofile since macOS defaults to zsh)
  • IOKit power management — kIOPMAssertionTypePreventUserIdleSystemSleep + NetworkClientActive keep WiFi alive during display sleep. Assertion name masquerades as com.apple.apsd
  • DYLD spawn — DYLD_INSERT_LIBRARIES process spawning works with SIP enabled (user-installed binaries only). Ad-hoc code signing for loader dylib. task_for_pid injection when SIP is disabled
  • Process masquerading — setprogname() hides agent name in ps output
  • SOCKS5 proxy — full SOCKS support on macOS agents

Cloud BOFs

  • 15 AWS BOFs — credential discovery (IMDS v1/v2, env vars, SSO caches, Credential Manager, process memory), IAM enumeration, role assumption, S3/EC2/Lambda/Secrets Manager/SSM access, SSM exec, EC2 Instance Connect, Lambda invoke. SigV4 signing built-in
  • 8 Azure ARM BOFs — managed identity tokens, credential search, resource enumeration (VMs, Key Vault, Storage), blob download, VM Run Command execution
  • 14 Entra ID BOFs — identity enumeration (users, groups, roles, service principals, conditional access), app secret listing/addition, OAuth grants, role assignment, PIM eligible roles
  • 8 GCP Cloud BOFs — metadata token theft, credential file scanning, identity validation, VM enumeration, GCS bucket/object access, Secret Manager secrets, IAM enumeration. OAuth2 token auth via GCP metadata server or operator-supplied token
  • 3 Kubernetes BOFs — pod/service/namespace enumeration, secret dumping, RBAC analysis
  • All cloud BOFs ship as both Windows COFF and Linux/macOS .so — work on all three platforms

CDN Redirectors

  • AWS CloudFront — CDN redirector config generated from the CLI (redirector cloudfront --origin <host>) or the Web UI Redirector page. Agents connect to d*.cloudfront.net with a valid AWS TLS certificate. C2 server IP hidden from the target network
  • Azure Front Door — CDN redirector config generated from the CLI or Web UI. Agents connect to *.azurefd.net with a valid Microsoft TLS certificate
  • GCP Cloud CDN — CDN redirector config generated from the CLI (redirector gcp --origin <host>) or the Web UI Redirector page. Agents connect to a Google Cloud IP with a Google-managed TLS certificate
  • Traffic blending — C2 traffic indistinguishable from any other CDN-hosted service on the wire. Not domain fronting — legitimate CDN routing

BOF Counts

  • Total: 431 BOFs (217 Windows + 115 Linux + 99 macOS), up from 245 in v2.2.0
  • 45 cloud BOFs across AWS, Azure, Entra ID, GCP, and Kubernetes
  • Full cross-platform coverage — Windows, Linux, and macOS agents all shipped
v2.2.0 September 15, 2026

DNS-over-HTTPS, Resumable Downloads, Operator Collaboration

DNS-over-HTTPS Transport

  • DOH transport — new transport mode sends DNS queries as HTTPS POST requests to configurable resolvers (Cloudflare, Google, custom). Blends C2 traffic into legitimate HTTPS DNS traffic. Windows and Linux
  • 5 transports total — HTTPS, SMB, TCP, DNS, and now DOH

Resumable File Transfers

  • Offset-based resume — interrupted downloads resume from last byte received. Server reads .part file size and sends offset to implant, which seeks before reading
  • 20-byte chunk header — widened from 16 bytes to support files larger than 4 GB (totalSize split into lo/hi uint32 pair)
  • CLI — downloads lists all downloads with status/progress, downloads resume <id> resumes partial or interrupted transfers
  • Web UI — Downloads page with Resume button, inline status badges, and file preview for images
  • Download notifications — red badge on Downloads sidebar tab for completed transfers, matching the Sessions tab pattern
  • Error handling — failed downloads show as red “Error: Download failed” with reason in both CLI and Web UI session output

Anti-Analysis & Anti-Virtualization

  • CPUID VM detection — check_vm() uses CPUID leaf 1 ECX bit 31 for hypervisor detection, with fallback to hostname sandbox keyword check
  • Split toggles — anti-analysis split into two independent controls: parent process check and VM detection. Configurable separately in CLI (--no-parent-check, --no-vm-check) and Web UI build page

Operator Collaboration

  • Operation chat — real-time messaging between operators, SSE-backed, SQLite-persisted, with pinnable messages. Floating chat sidebar in Web UI, chat command in CLI
  • Session tags — label sessions with arbitrary tags for organizing engagements. Inline add/remove in Web UI Sessions table, tag/untag commands in CLI
  • Timeline — unified event timeline page with color-coded event types across all sessions
  • Engagement reports — report engagement [path] generates Markdown summary of sessions, credentials, MITRE coverage, and pinned chat messages

Credential BOFs

  • dpapi-creds — DPAPI credential blob decryption for Windows Credential Manager
  • dpapi-hash — extract DPAPI master key hash for offline cracking
  • dump-chromium — credential extraction from Chrome, Edge, Brave, Opera, and Vivaldi with v10/v20 app-bound key support
  • dump-certs — export certificates from Windows certificate stores
  • dump-vault — Windows Credential Vault enumeration via VaultCli API

Evasion Improvements

  • Tampered syscall decoy rotation — decoy syscall target randomized per build from pool, no two builds share the same decoy
  • Argument spoofing — PEB CommandLine overwrite for migrate and injection targets. Spawned processes show a configurable decoy command line
  • COFF .pdata registration — BOF exception unwind data registered with RtlAddFunctionTable for proper structured exception handling in BOFs
  • Ghost/herpaderp cleanup — process ghosting uses rename+hide instead of random hex filenames, cleaner on-disk forensics

Operational Controls

  • KillDate — implant self-terminates after a configured UTC timestamp. Enforced at every beacon cycle
  • WorkingHours — implant only beacons during configured hour range (e.g., 08:00-18:00). Sleeps through off-hours to blend with business traffic

CLI & Web UI Polish

  • Red error messages — all [!] errors and download failures render in red across the CLI
  • Platform-aware BOF errors — running a Windows-only BOF on Linux (or vice versa) returns a clear message instead of “unknown command”
  • Argument-aware autocomplete — tab completion shows argument hints and descriptions for all commands in CLI and Web UI
  • Unified CLI — removed embedded console (krait run), single remote CLI via krait connect
  • Migrate radio groups — injection method flags in Web UI build page use mutually exclusive radio buttons instead of checkboxes
  • Web UI command filtering — CLI-only commands (downloads, operators, sessions, etc.) removed from Web UI autocomplete

Other

  • 10 new BOFs added since v2.1.0, bringing the total to 178 Windows + 67 Linux (245 total)
v2.1.0 August 29, 2026

Chrome Extension C2, Web UI Upgrades, Operator QoL

Chrome Extension C2 Persistence

  • Silent extension install — chrome-persist-install deploys a Chrome/Edge extension and recalculates Secure Preferences HMAC so it survives browser restart. Supports --browser chrome|edge, --profile, --cover (browser-aware cover names: chromeUpdate/edgeUpdate), --force
  • Extension removal — chrome-persist-remove cleanly uninstalls the extension
  • 6 extension BOFs for browser-context operations:
    • ext-cookies — dump browser cookies with optional domain filter
    • ext-tabs — list open browser tabs
    • ext-screenshot — capture visible tab as PNG
    • ext-history — browse history with search
    • ext-navigate — navigate active tab to URL
    • ext-nmh — execute commands via Native Messaging Host proxy

Web UI Upgrades

  • Pivot graph — interactive SVG topology view with drag, pan, zoom, and agent detail panel. Click “Interact” to jump to agent console
  • File browser — remote filesystem navigation with breadcrumb path, sortable columns, file preview pane, download/delete actions
  • Process browser — sortable process table with security process highlighting, right-click context menu (steal-token, migrate, suspend, kill)
  • Screenshot/keylog viewer — inline screenshot preview and keylog display in agent console
  • Download manager — centralized view of downloaded files with inline previews
  • Credential store — auto-extraction from BOF output (hashdump, enum-creds, make-token, etc.), centralized credential management page with search and export

Operator Improvements

  • Verbosity levels — verbose 0 shows results only (no task lifecycle messages), verbose 1 (default) shows operational messages. Available in CLI, embedded console, and Web UI
  • Execute-assembly consolidation — collapsed 6 variants down to one: execute-assembly now runs in-process with full evasion (HWBP AMSI/ETW bypass + LoadLibrary proxy). Fork & run and no-evasion variants removed
  • BOF chaining in Web UI — chain command now works from the Web UI (previously CLI-only)
  • Chrome extension cover names — browser-aware cover names auto-selected based on --browser flag

Other

  • 20 new BOFs added since v2.0.0, bringing the total to 168 Windows + 67 Linux (235 total)
  • Python 3.11 compatibility fix for Nuitka container builds
v2.0.0 July 17, 2026

Linux Agent, Advanced Evasion, Credential Theft

Linux Agent

Full native Linux implant with the same wire protocol as Windows:

  • HTTPS transport via OpenSSL
  • .so module loader (memfd_create + dlopen for fileless execution)
  • Direct syscall stubs (18 raw syscalls, zero hookable PLT entries)
  • Sleep obfuscation (XOR .text section during nanosleep)
  • String obfuscation (compile-time XOR, zero cleartext IOCs)
  • Anti-sandbox (CPU count, uptime, DMI vendor, disk size)
  • Anti-debug (ptrace self-check, /proc/self/status TracerPid)
  • Ptrace-based process injection (memfd_create + execveat in target)
  • Fileless persistence (crontab + memfd_create one-liner)
  • Polymorphic builds (function reorder, junk code, padding, decoy strings)
  • Process masquerade (argv[0] + prctl PR_SET_NAME)

Windows Evasion Upgrades

  • Tampered syscalls — VEH handler intercepts at ntdll syscall instruction boundary, swaps SSN and args. Return address points into ntdll, defeating return-address analysis.
  • Foliage sleep obfuscation — APC-based alternative to Ekko. 7-step ROP chain via suspended thread + NtContinue APCs. No RWX shellcode page.
  • PE fluctuation — Timer-driven encrypt-at-rest with VEH handler. Only the accessed page is live at any moment.
  • Heap encryption — HeapWalk() encrypts all non-default process heaps during sleep. Catches allocations SleepMaskRegister doesn’t know about.
  • Process ghosting — SEC_IMAGE from delete-pending file. On-disk forensics find nothing.
  • Process herpaderping — NtCreateSection then overwrite file with clean PE before process runs.
  • Module overloading — SEC_IMAGE mapping without PEB loader-list entry. Alternative to module stomping.
  • Threadless injection — Hook target export → CALL to memory hole → self-healing shellcode. No thread, no APC, no context modification.
  • LoadLibrary Proxy v2 — Selective manual mapping of clr.dll/clrjit.dll to suppress kernel-mode image-load notifications. API set resolution, TLS processing, fail-open design.

Credential Theft

  • Chrome credential dump — App-Bound Encryption v20+ full decryption chain (DPAPI as SYSTEM via csrss token theft → CNG NCryptDecrypt → AES-256-GCM per cookie/login)
  • Firefox credential dump — key4.db ASN.1 DER parsing → PBKDF2-SHA256 → AES-256-CBC master key → logins.json decrypt
  • RDP credential theft — DLL injection into mstsc.exe with hardware breakpoints on SspiPrepareForCredRead + CredIsMarshaledCredentialW + CryptProtectMemory
  • LSASS handle duplication — NtQuerySystemInformation(SystemHandleInformation) + DuplicateHandle instead of OpenProcess
  • Silent process exit dump — WerFault.exe triggered via RtlReportSilentProcessExit registry configuration
  • Race condition dump — seclogon.dll CreateProcessWithLogonW race for LSASS handle acquisition
  • SAM dump — In-memory extraction via registry API with PEK decryption (no files on disk)

Other Additions

  • ETW session hijacking — Restart named ETW sessions with bogus LogFileName (Procmon, Sysmon)
  • Better ETW patching — NOP out call EtwpEventWriteFull inside EtwEventWrite body (alternative to ret-patch)
  • DLL load notification unhooking — Remove EDR LdrRegisterDllNotification callbacks from PEB
  • BOF chaining — Queue up to 16 BOFs as single atomic task
  • Machine lock — Bind agent to specific hardware via SMBIOS UUID

Operator

  • Debug build options (--debug-stub, --debug-migrate) removed from CLI/web UI (still available in build_prod.py for development)
v1.0.0 July 8, 2026

Initial Release

Implant

  • COFF/BOF execution engine with 162+ commands
  • Four transport protocols: HTTPS, SMB, TCP, DNS
  • Seven delivery formats: EXE, DLL, shellcode, service, XLL, CPL, stager
  • Full evasion suite: indirect syscalls, Ekko sleep encryption, HWBP bypass, stack spoofing, module stomping, phantom DLL hollowing
  • Process migration with section mapping, context hijack, delayed suspend
  • Traffic mimicry with 5 SaaS profiles and matching PE covers
  • Sleep mask with stack encryption
  • Peer reconnection for SMB/TCP children

Operator

  • Client-server FastAPI architecture with headless mode
  • Multi-operator JWT authentication with presence tracking
  • Web dashboard (React + Tailwind)
  • Interactive CLI with tab completion
  • AI operator interface (MCP server)
  • SOCKS5 proxy tunneling
  • MITRE ATT&CK mapping (74 techniques)
  • Agent topology graph
  • Redirector config generators (nginx + DNS)