Navigation X
ALERT
Click here to register with a few steps and explore all our cool stuff we have to offer!



 54623

ToRat - Open Source RAT over Tor

by aethernaut - 17 May, 2020 - 04:20 PM
This post is by a banned member (dom12341) - Unhide
dom12341  
Registered
19
Posts
0
Threads
(17 May, 2020 - 04:20 PM)aethernaut Wrote: Show More
"ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication"

This guy is making what I think all RATs should be. Check it out and if you're a go programmer maybe even contribute.



"Current Features
  • RPC (Remote procedure Call) based communication for easy addition of new functionallity
  • Automatic upx leads to client binaries of ~10MB with embedded Tor
  • the ToRAT_client communicates over TLS encrypted RPC proxied through Tor with the ToRat_server (hidden service)
    •  anonymity of client and server
    •  end-to-end encryption
  • Cross Platform reverse shell (Windows, Linux, Mac OS)
  • Windows:
    • Multiple User Account Control Bypasses (Privilege escalation)
    • Multiple Persistence methods (User, Admin)
  • Linux:
    • Multiple Persistence methods (User, Admin)
  • optional transport without Tor e.g. Use Tor2Web, a DNS Hostname or public/ local IP
    •  smaller binary ~7MB upx'ed
    •  anonymity of client and server
  • embedded Tor
  • Unique persistent ID for every client
    • give a client an Alias
    • all Downloads from client get saved to ./$ID/$filename
  • sqlite via gorm for storing information about the clients

qdqdq
This post is by a banned member (XDonCrow) - Unhide
XDonCrow  
Registered
455
Posts
20
Threads
Thanks
[Image: zmA34wW.gif]
This post is by a banned member (DiegoUssy) - Unhide
DiegoUssy  
Registered
38
Posts
0
Threads
(17 May, 2020 - 04:20 PM)aethernaut Wrote: Show More
"ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication"

This guy is making what I think all RATs should be. Check it out and if you're a go programmer maybe even contribute.



"Current Features
  • RPC (Remote procedure Call) based communication for easy addition of new functionallity
  • Automatic upx leads to client binaries of ~10MB with embedded Tor
  • the ToRAT_client communicates over TLS encrypted RPC proxied through Tor with the ToRat_server (hidden service)
    •  anonymity of client and server
    •  end-to-end encryption
  • Cross Platform reverse shell (Windows, Linux, Mac OS)
  • Windows:
    • Multiple User Account Control Bypasses (Privilege escalation)
    • Multiple Persistence methods (User, Admin)
  • Linux:
    • Multiple Persistence methods (User, Admin)
  • optional transport without Tor e.g. Use Tor2Web, a DNS Hostname or public/ local IP
    •  smaller binary ~7MB upx'ed
    •  anonymity of client and server
  • embedded Tor
  • Unique persistent ID for every client
    • give a client an Alias
    • all Downloads from client get saved to ./$ID/$filename
  • sqlite via gorm for storing information about the clients

ty
This post is by a banned member (DiegoUssy) - Unhide
DiegoUssy  
Registered
38
Posts
0
Threads
(17 May, 2020 - 04:20 PM)aethernaut Wrote: Show More
"ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication"

This guy is making what I think all RATs should be. Check it out and if you're a go programmer maybe even contribute.



"Current Features
  • RPC (Remote procedure Call) based communication for easy addition of new functionallity
  • Automatic upx leads to client binaries of ~10MB with embedded Tor
  • the ToRAT_client communicates over TLS encrypted RPC proxied through Tor with the ToRat_server (hidden service)
    •  anonymity of client and server
    •  end-to-end encryption
  • Cross Platform reverse shell (Windows, Linux, Mac OS)
  • Windows:
    • Multiple User Account Control Bypasses (Privilege escalation)
    • Multiple Persistence methods (User, Admin)
  • Linux:
    • Multiple Persistence methods (User, Admin)
  • optional transport without Tor e.g. Use Tor2Web, a DNS Hostname or public/ local IP
    •  smaller binary ~7MB upx'ed
    •  anonymity of client and server
  • embedded Tor
  • Unique persistent ID for every client
    • give a client an Alias
    • all Downloads from client get saved to ./$ID/$filename
  • sqlite via gorm for storing information about the clients

ty

Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
or
Sign in
Already have an account? Sign in here.


Forum Jump:


Users browsing this thread: 2 Guest(s)