Python based backdoor that uses Gmail to exfiltrate data through attachment. This RAT will help during red team engagements to backdoor any Windows machines. It tracks the user activity using screen capture and sends it to an attacker as an e-mail attachment.

RAT Architecture Diagram

[Image: 54605214-dd51f400-4a9c-11e9-8b51-a225b13ecd0d.png]

On the first run of the Powershell-RAT user will get options as below:

[Image: 37453784-e926b64a-288c-11e8-9c8d-abaaf1b7dd3d.png]

Using Hail Mary option to backdoor a Windows machine:

[Image: 37453816-fdfffaea-288c-11e8-9a60-0adcd0dc4599.png]

[Image: 37453833-0c7f3e78-288d-11e8-969e-5499cf53f2fd.png]

Data exfiltrated as an email attachment using Gmail:

[Image: 37453864-233384d0-288d-11e8-8699-e5dbe149925c.png]

[Image: Vs4P58c.png]


Been playing around with Cerberus Linux and getting used to it. This will be interesting to try out, ty


