This lesson was written by Forums drcrypter.ru and Muddyc3, coded in Python version 2.7 with Powershell.
The required payload for the agent and part of the C2 code were missing, so no one published a working code, and it was forgotten until now, when it was fully leaked with 100% source code.
It's super interesting because it was developed by APT Iran hackers, and they have three APTs: 33, 34, and 35. According to the RecordedFuture website
another thing many tools by APT Iran powerfull used to Hack The World long time
We can call these special weapons and more tools soon by APT Iran.
I recommend you use CMDER in my file to run support color and make it easy on your eyes.
This is a working POC the leaked MuddyC3 C2 . its include below fetaures right now :
1) agent reconnect
2) load modules
3) send commands and recive results
4) create powershell payloads
As you can see if you have Experinced Powershell Empire or something about powershell in Veil evasion that easy to learn and fast understand
Here Old day it was tested by someone to proof but you can try reFUD with this again. Good luck and try playing with it.
The required payload for the agent and part of the C2 code were missing, so no one published a working code, and it was forgotten until now, when it was fully leaked with 100% source code.
It's super interesting because it was developed by APT Iran hackers, and they have three APTs: 33, 34, and 35. According to the RecordedFuture website
another thing many tools by APT Iran powerfull used to Hack The World long time
We can call these special weapons and more tools soon by APT Iran.
I recommend you use CMDER in my file to run support color and make it easy on your eyes.
This is a working POC the leaked MuddyC3 C2 . its include below fetaures right now :
1) agent reconnect
2) load modules
3) send commands and recive results
4) create powershell payloads
As you can see if you have Experinced Powershell Empire or something about powershell in Veil evasion that easy to learn and fast understand
Here Old day it was tested by someone to proof but you can try reFUD with this again. Good luck and try playing with it.
drcrypter.ru
Last edited: