githubEdit

appleEvilOSX

An evil RAT (Remote Administration Tool) for macOS / OS X.

Features

  • Emulate a terminal instance

  • Simple extendable modulearrow-up-right system

  • No bot dependencies (pure python)

  • Undetected by anti-virus (OpenSSL AES-256arrow-up-right encrypted payloads)

  • Persistent

  • GUI and CLI support

  • Retrieve Chrome passwords

  • Retrieve iCloud tokens and contacts

  • Retrieve/monitor the clipboard

  • Retrieve browser history (Chrome and Safari)

  • Phisharrow-up-right for iCloud passwords via iTunes

  • iTunes (iOS) backup enumeration

  • Record the microphone

  • Take a desktop screenshot or picture using the webcam

  • Attempt to get root via local privilege escalation

How To Use

Warning: Because payloads are created unique to the target system (automatically by the server), the server must be running when any bot connects for the first time.

Advanced users

There's also a CLI for those who want to use this over SSH:

Screenshots

CLIarrow-up-right GUIarrow-up-right


REFERENCES

Last updated