• Earn real money by being active: Hello Guest, earn real money by simply being active on the forum — post quality content, get reactions, and help the community. Once you reach the minimum credit amount, you’ll be able to withdraw your balance directly. Learn how it works.

RAT ToRAT

Status
Not open for further replies.

Penisoooo

Member
User
Joined
Jun 28, 2024
Messages
5
Reputation
0
Reaction score
16
Points
3
Credits
0
‎1 Year of Service‎
100%
This link is hidden for visitors. Please Log in or register now.


This link is hidden for visitors. Please Log in or register now.
 
This link is hidden for visitors. Please Log in or register now.
 
This link is hidden for visitors. Please Log in or register now.
 
This link is hidden for visitors. Please Log in or register now.


A Cross Platform Remote Administration tool written in Go using Tor as its transport mechanism currently supporting Windows, Linux, MacOS clients.


DISCLAIMER

USE FOR EDUCATIONAL PURPOSES ONLY


Wiki

This link is hidden for visitors. Please Log in or register now.



Preview

This link is hidden for visitors. Please Log in or register now.



Client Commands





Command


Info






cd


change the working directory of the client




ls


list the content of the working directory of the client




shred


delete files/ directories unrecoverable




screen


take a Screenshot of the client




cat


view Textfiles from the client including .docx, .rtf, .pdf, .odt




alias


give the client a custom alias




down


download a file from the client




up


upload a file to the client




speedtest


speedtest a client's internet connection




hardware


collects a variety of hardware specs from the client




netscan


scans a clients entire network for online devices and open ports




gomap


scan a local ip on a clients network for open ports and services




escape


escape a command and run it in a native shell on the client




reconnect


tell the client to reconnect




help


lists possible commands with usage info




exit


background current session and return to main shell






Server Commands





Command


Info






select


select client to interact with




list


list all connected clients




alias


select client to give an alias




cd


change the working directory of the server




help


lists possible commands with usage info




exit


exit the server






Current Features


Architecture

  • RPC (Remote procedure Call) based communication for easy addition of new functionality
  • Automatic upx leads to client binaries of ~6MB with embedded Tor
  • sqlite via gorm for storing information about the clients
  • client is obfuscated via 
    This link is hidden for visitors. Please Log in or register now.



Server Shell

  • Cross Platform reverse shell (Windows, Linux, Mac OS)
  • Supports multiple connections
  • Welcome Banner
  • Colored Output
  • Tab-Completion of:



    Commands
  • Files/ Directories in the working directory of the server

[*]Unique persistent ID for every client



  • give a client an Alias
  • all Downloads from client get saved to ./$ID/$filename




Persistence

  • Windows:



     Multiple User Account Control Bypasses (Privilege escalation)
  •  Multiple Persistence methods (User, Admin)

[*]Linux:



  •  Multiple Persistence methods (User, Admin)




Tor

  • Fully embedded Tor within go
  • the ToRAT_client communicates over TLS encrypted RPC proxied through Tor with the ToRat_server (hidden service)



     anonymity of client and server
  •  end-to-end encryption

[*]optional transport without Tor e.g. Use Tor2Web, a DNS Hostname or public/ local IP



  •  smaller binary ~3MB upx'ed
  •  anonymity of client and server




Upcoming Features

  •  Bulk Commands
  •  Persistence and privilege escalation for Linux
  •  Persistence and privilege escalation for Mac OS
  •  Support for Android and iOS (needs fix of 
    This link is hidden for visitors. Please Log in or register now.
    )
  •  
    This link is hidden for visitors. Please Log in or register now.

 
Status
Not open for further replies.
Back
Top