dEEpEst
☣☣ In The Depths ☣☣
Staff member
Administrator
Super Moderator
Hacker
Specter
Crawler
Shadow
- Joined
- Mar 29, 2018
- Messages
- 13,861
- Solutions
- 4
- Reputation
- 32
- Reaction score
- 45,552
- Points
- 1,813
- Credits
- 55,350
7 Years of Service
56%
RAT-via-Telegram
Windows Remote Administration Tool via Telegram (now in Python 3.7!) | Originally created by
Why another one?
[*]This RAT overcomes both these issues by using the Telegram bot API.
Features:
Thanks
:
& More coming soon!
Screenshots:
Installation & Usage:
- A folder named `RATAttack` will be created in your working directory containing `keylogs.txt` and any files you upload to the bot.
Deploy quickly:
Commands:
When using the below commands; use / as a prefix. For example: /pc_info.
arp - display arp table
capture_pc - screenshot PC
cmd_exec - execute shell command
cp - copy files
cd - change current directory
delete - delete a file/folder
download - download file from target
decode_all - decode ALL encoded local files
dns - display DNS Cache
encode_all - encode ALL local files
freeze_keyboard - enable keyboard freeze
unfreeze_keyboard - disable keyboard freeze
get_chrome - Get Google Chrome's login/passwords
hear - record microphone
ip_info - via ipinfo.io
keylogs - get keylogs
ls - list contents of current or specified directory
msg_box - display message box with text
mv - move files
pc_info - PC information
ping - makes sure target is up
play - plays a youtube video
proxy - opens a proxy server
pwd - show current directory
python_exec - interpret python
reboot - reboot computer
run - run a file
schedule - schedule a command to run at specific time
self_destruct - destroy all traces
shutdown - shutdown computer
tasklist - display services and processes running
to - select targets by it's name
update - update executable
wallpaper - change wallpaper
You can copy the above to update your command list via BotFather so you don't have to type them manually.
Compiling:
How To Compile:
Either:
Replace your path in compileAndRun.bat (running this will actually run the executable)
Or:
Modifying Settings:
Download:
Windows Remote Administration Tool via Telegram (now in Python 3.7!) | Originally created by
This link is hidden for visitors. Please Log in or register now.
Why another one?
- The current Remote Administration Tools in the market face 2 major problems:
Lack of encryption.
- Require port forwarding in order to control from hundreds of miles.
[*]This RAT overcomes both these issues by using the Telegram bot API.
Fully encrypted. The data being exchanged cannot be spied upon using MITM tools.
- Telegram messenger app provides a simple way to communicate to the target without configuring port forward before hand on the target.
Features:
- Keylogger with window title log included
- Get target PC's Windows version, processor and more
- Get target PC's IP address information and approximate location on map
- Delete, Move files
- Show current directory
- Change current directory
- List current or specified directory
- Download any file from the target
- Upload local files to the target. Send your image, pdf, exe or anything as file to the Telegram bot
- Autostart playing a video in fullscreen and no controls for a youtube video on target
- Take Screenshots
- Execute any file
- Access to microphone
- Start HTTP Proxy Server
- Freeze target's keyboard
- Schedule tasks to run at specified datetime
- Encode/Decode all local files
- Ping targets
- Update .exe -- thanks
This link is hidden for visitors. Please Log in or register now.
- Self-Destruct RAT
- Change wallpaper from file or url
- Execute cmd shell
- Take snapshots from the webcam (if attached)
- Execute arbitrary python 3.7 on the go
- Freeze target's mouse
- [TODO] Browser (IE, Firefox, Chrome) cookies retrieval
- [TODO] Password retrieval
- [TODO] Monitor web traffic (graphically?)
- [TODO] Bandwidth monitoring (stepping stone to web traffic monitoring) - started 28/10/2018
- [TODO] Fine-tuning scripting (i.e.: if app x is opened y is executed)
- [TODO] Capture clipboard (Text, Image)
- [TODO] Hide desktop icons
- [TODO] Audio compression
- [TODO] Name server lookup (/nslookup -
This link is hidden for visitors. Please Log in or register now.
Thanks
This link is hidden for visitors. Please Log in or register now.
- Chrome login/password retrieval
- Display ARP table
- Get active processes and services
- Shutdown/Reboot computer
- Display DNS Cache
& More coming soon!
Screenshots:
This link is hidden for visitors. Please Log in or register now.
Installation & Usage:
- Clone this repository.
- Set up a new Telegram bot talking to the BotFather.
- Copy this token and replace it in the beginning of the script.
- Install the dependencies: pip install -r requirements.txt.
- Install PyHook and PyAudio 64-bit or 32-bit depending on your system from
This link is hidden for visitors. Please Log in or register now.
- To run the script: python RATAttack.py.
- Find your bot on telegram and send some command to the bot to test it.
- To restrict the bot so that it responds only to you, note down your chat_id from the console and replace it in the script and comment out the line return True. Don't worry, you'll know when you read the comments in the script.
This link is hidden for visitors. Please Log in or register now.
- A folder named `RATAttack` will be created in your working directory containing `keylogs.txt` and any files you upload to the bot.
Deploy quickly:
- Clone the repo
- Create a bot with BotFather and save the token
- Go into RATAttack.py and replace tokenwith the token you saved
- Run setup_rat.py
Commands:
When using the below commands; use / as a prefix. For example: /pc_info.
arp - display arp table
capture_pc - screenshot PC
cmd_exec - execute shell command
cp - copy files
cd - change current directory
delete - delete a file/folder
download - download file from target
decode_all - decode ALL encoded local files
dns - display DNS Cache
encode_all - encode ALL local files
freeze_keyboard - enable keyboard freeze
unfreeze_keyboard - disable keyboard freeze
get_chrome - Get Google Chrome's login/passwords
hear - record microphone
ip_info - via ipinfo.io
keylogs - get keylogs
ls - list contents of current or specified directory
msg_box - display message box with text
mv - move files
pc_info - PC information
ping - makes sure target is up
play - plays a youtube video
proxy - opens a proxy server
pwd - show current directory
python_exec - interpret python
reboot - reboot computer
run - run a file
schedule - schedule a command to run at specific time
self_destruct - destroy all traces
shutdown - shutdown computer
tasklist - display services and processes running
to - select targets by it's name
update - update executable
wallpaper - change wallpaper
You can copy the above to update your command list via BotFather so you don't have to type them manually.
Compiling:
How To Compile:
Either:
Replace your path in compileAndRun.bat (running this will actually run the executable)
Or:
Code:
Run `pyinstaller --onefile --noconsole C:\path\to\RATAttack.py`. You can also pass `--icon=<path\to\icon.ico>` to use any custom icon.
- Once it is compiled successfully, find the .exe file in C:\Python37\Scripts\dist\. You can change the name of the .exe to anything you wish.
- BEWARE! If you run the compiled .exe, the script will move itself to startup and start with your PC to run at startup. You can return to normal by using the /self_destructoption or manually removing C:\Users\Username\AppData\Roaming\Portal directory and C:\Users\Username\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\portal.lnk(although I recommend removing them manually for the time being).
Modifying Settings:
- You can also modify the name of hidden .exe file and location & name of the folder where the hidden .exe will hide itself. To do this; modify compiled_name and hide_folder respectively.
- Assign your known chat ids to beginning of RATAttack.py
Download:
To see this hidden content, you must like this content.