awesome-malware
Malware repository
A curated collection of malware tools for analysis and demonstration purposes
![]()
A curated collection of awesome malware, botnets, and other post-exploitation tools.
245 stars
20 watching
33 forks
last commit: over 4 years ago
Linked from 1 awesome list
awesomeawesome-listcomputer-securitycybersecuritymalwarepost-exploitation
Analysis and reverse engineering | |||
| theZoo | Repository of live malwares for your own joy and pleasure, created to make the possibility of malware analysis open and available to the public | ||
Botnets | |||
| Idisagree | 174 | over 3 years ago | Control remote computers using Discord bot and Python 3 |
Command and Control | |||
| Browser Exploitation Framework (BeEF) | 9,918 | 11 months ago | Command and control server for delivering exploits to commandeered Web browsers |
| Merlin | 5,110 | 11 months ago | Cross-platform post-exploitation HTTP/2 command and control server and agent written in golang |
| SILENTTRINITY | 2,204 | almost 2 years ago | Asynchronous, collaborative post-exploitation agent powered by Python and .NET's DLR |
Credential Stuffing Account Checkers | |||
| Reference | Black Bullet - Single-threaded account checker with captcha bypass features and Selenium WebDriver support, sold for about $30 to $50. ( ) | ||
| Private Keeper | Russian language account checker and takeover tool, sold at prices starting from approximately $1 USD | ||
| SNIPR | Windows toolkit for credential stuffing across Web (HTTP/S) and email (IMAP) attack surfaces with the ability to encrypt and re-sell ATO configurations, sold for about $20 | ||
| Reference | STORM - Flexible account checker with Cloudflare protection bypass features written in C#. ( ) | ||
| Sentry MBA | Among the oldest and longest in-use account checkers, using OCR for captcha bypass but unable to pass JavaScript anti-bot challenges, sold for between $5 and $20 per configuration file. ( ) | ||
| Reference | Woxy - Email account checker with built-in support for automating password reset and searching email content for valuable information, now cracked and available free of charge. ( ) | ||
Evasion | |||
| CheckPlease | 904 | over 4 years ago | Sandbox evasion modules written in PowerShell, Python, Go, Ruby, C, C#, Perl, and Rust |
Keyloggers | |||
| TechNowLogger | 448 | about 1 year ago | Windows/Linux keylogger generator which sends key-logs via email with other juicy target info |
Phishing kits | |||
| ActorExpose/PhishKits | Collection of phishing kits provided to the public to make the Internet a safer environment | ||
Remote Administration Tools (RATs) | |||
| Bella | 187 | about 3 years ago | Pure Python post-exploitation data mining and remote administration tool for macOS |
| Empire | Pure PowerShell post-exploitation agent built on cryptologically-secure communications and a flexible architecture | ||
| EvilOSX | 2,286 | almost 5 years ago | Modular RAT that uses numerous evasion and exfiltration techniques out-of-the-box |
| Pupy | 8,490 | over 1 year ago | Low-footprint, cross-platform (Windows, Linux, macOS, Android) RAT featuring all-in-memory execution guideline written in Python |
| RedPeanut | 327 | over 2 years ago | Small RAT developed in .Net Core 2 and its agent in .Net 3.5/4.0, weaponized with several additional utilities |
| Slackor | 458 | over 2 years ago | Golang implant that uses Slack as a command and control server |
| Twittor | 765 | about 5 years ago | Stealthy Python based backdoor that uses Twitter (Direct Messages) as a command and control server |
Rootkits | |||
| Adore-NG | 206 | almost 10 years ago | Rootkit adapted for the 2.6 and 3.x Linux kernels |
| AdoreForAndroid | 37 | about 11 years ago | Adore rootkit ported to Android |
| Diamorphine | 1,865 | about 2 years ago | LKM rootkit for Linux Kernels 2.6.x, 3.x, and 4.x |
| Masochist | 124 | almost 11 years ago | Framework for creating XNU based rootkits useful in OS X and iOS security research |
| Vector-EDK | 135 | over 10 years ago | Commercial UEFI rootkit illegally sold by Hacking Team to numerous governments, leaked by hacker Phineas Phisher in 2015, and the basis of the |
| vlany | 947 | almost 5 years ago | Linux rootkit |
Web Shells | |||
| BlackArch Webshells Collection | 896 | about 2 years ago | Various webshells that can be installed as a package on BlackArch Linux |
| DAws | 573 | over 8 years ago | Advanced Web shell |
| PHP-backdoors | 2,211 | over 1 year ago | Collection of PHP backdoors, for educational and/or testing purposes only |
| PHP Exploit Scripts | 841 | over 1 year ago | Collection of PHP exploit scripts (often but not necessarily always backdoors or web shells), found when investigating hacked servers |
| PHP WebShells collection | 1,888 | over 4 years ago | Repository of common PHP Web shells, somewhat dated |
| PhpSploit | 2,237 | over 1 year ago | Remote control framework, aiming to provide a stealth interactive shell-like connection over HTTP between client and web server |
| SharPyShell | 922 | almost 2 years ago | Tiny and obfuscated ASP.NET webshell for C# web applications |
| SecLists Web Shells | 59,209 | 11 months ago | Examples of core Web shell functionality in PHP, JSP, ASP(X), ColdFusion, and more |
| Weevely | 3,216 | about 1 year ago | Extensible PHP Web shell with numerous out-of-the-box modules |
More related projects:
-
emilyanncr/windows-post-exploitation
-
nextronsystems/aptsimulator
-
s1ckb0y1337/active-directory-exploitation-cheat-sheet
-
tennc/webshell
-
bats3c/shad0w
-
donnemartin/haxor-news
-
geeksniper/active-directory-pentest
-
foospidy/payloads
-
gentilkiwi/mimikatz
-
donnemartin/saws
-
deimosc2/deimosc2
-
gentilkiwi/kekeo
-
goblinfactory/konsole
-
govolution/avet
-
empireproject/empire