• Earn real money by being active: Hello Guest, earn real money by simply being active on the forum — post quality content, get reactions, and help the community. Once you reach the minimum credit amount, you’ll be able to withdraw your balance directly. Learn how it works.

RedditC2: Abusing Reddit API to host the C2 traffic

Status
Not open for further replies.

itsMe

*KillmeMories*
Staff member
Administrator
Super Moderator
Hacker
Specter
Crawler
Shadow
Joined
Jan 8, 2019
Messages
56,602
Solutions
2
Reputation
32
Reaction score
100,445
Points
2,313
Credits
32,540
‎6 Years of Service‎
 
76%
screenshot-10599.png


Abusing Reddit API to host the C2 traffic, since most of the blue-team members use Reddit, might be a great way to make the traffic look legit.

Workflow

Teamserver

    Go to the specific Reddit Post & post a new comment with the command ("in: ")
    Read for new comment which includes the word "out:"
    If no such comment is found, go back to step 2
    Parse the comment, decrypt it and read it's output
    Edit the existing comment to "executed", to avoid reexecuting it

Client

    Go to the specific Reddit Post & read the latest comment which includes "in:"
    If no new comment is detected, go back to step 1
    Parse the command out of the comment, decrypt it and execute it locally
    Encrypt the command's output and reply it to the respective comment ("out:" )

[Disclaimer]: Use of this project is for Educational/ Testing purposes only. Using it on unauthorised machines is strictly forbidden. If somebody is found to use it for illegal/ malicious intent, author of the repo will not be held responsible.

To see this hidden content, you must like this content.
 
Status
Not open for further replies.
Back
Top