• XSS.stack #1 – первый литературный журнал от юзеров форума

DarkGate Loader [ FUD // Bypass EDR // ADMIN & SYSTEM LPE // RedTeaming // EXE, DLL, LNK, URL, MSI, VBS ]

В этой теме можно использовать автоматический гарант!

Статус
Закрыто для дальнейших ответов.

RastaFarEye

HDD-drive
Забанен
Регистрация
09.08.2022
Сообщения
48
Реакции
45
Пожалуйста, обратите внимание, что пользователь заблокирован
This is a project that i have been working on since early 2017
I just now decided to rent it out, this project is a project that I have worked on for thousands of hours (more then 20,000)
This is the ultimate tool for pentesters/redteamers
Currently there are 4/10 slots available,


At the moment I don't intend to rent it to more than 10 people in order to keep this project private,
I also do not intend to rent it to people who do not understand its meaning and do not know how to use it because it is a destructive tool
That is not currently detected by any antivirus that knows how to do everything from privilege escalation and many more exploits and features that you won't find anywhere..

All our features are completely undetected because they run directly in memory without touching disk

*We have added the option of buying a package for one day so that you can check the quality of the product and get an impression
*Don't waste my time asking for discounts because the price I'm currently selling is very very cheap and the price is expected to rise in the coming months
*Read the thread carefully until the end

CURRENT PRICES

Payments only in crypto (BTC, ETH, MONERO, ETC..)
1 DAY PACKAGE -> 1000$ (YOU CAN BUY THIS PACKAGE ONLY 1 TIME WITH EACH EXPLOIT.IN ACCOUNT)
MONTHLY - 15,000$
1 YEAR UPDATED -> 100,000$

MAIN FEATURES ->

DOWNLOAD & EXECUTE ANY FILE DIRECTLY TO MEMORY (native,.net x86 and x64 files)
HVNC
HANYDESK
REMOTE DESKTOP
FILE MANAGER
REVERSE PROXY
ADVANCED BROWSERS PASSWORD RECOVERY ( SUPPORTING ALL BROWSER AND ALL PROFILES )
KEYLOGGER WITH ADVANCED PANEL
PRIVILEGE ESCALATION (NORMAL TO ADMIN / ADMIN TO SYSTEM)
WINDOWS DEFENDER EXCLUSION (IT WILL ADD C:/ FOLDER TO EXCLUSIONS )
DISCORD TOKEN STEALER
ADVANCED COOKIES STEALER + SPECIAL BROWSER EXTENSION THAT I BUILD FOR LOADING COOKIES DIRECTLY INTO A BROWSER PROFILE
BROWSER HISTORY STEALER
ADVANCED MANUAL INJECTION PANEL
CHANGE DOMAINS AT ANY TIME FROM ALL BOTS (Global extension)
CHANGE MINER DOMAIN AT ANY TIME FROM ALL BOTS (Global extension)
REALTIME NOTIFICATION WATCHDOG (Global extension)
ADVANCED CRYPTO MINER SUPPORTING CPU AND MULTIPLE GPU COINS (Global extension)
ROOTKIT WITHOUT NEED OF ADMINISTRATOR RIGHTS OR .SYS FILES (COMPLETLY HIDE FROM TASKMANAGER)
INVISIBLE STARTUP, IMPOSIBLE TO SEE THE STARTUP ENTRY EVEN WITH ADVANCED TOOLS
HIGH QUALITY FILE MANAGER, WITH FAST FILE SEARCH AND IMAGE PREVIEW

Some features like

*Capability to handle a very large amount of bots easily*
Extremely stable, can run for months non-stop, even if an error ocurrs it will continue running and a detailed bugreport will be generated
A well-spreaded build from 2018 yet fud by almost all avs (au3 script file)
And now my methods even improved so we usually not having a detection problems,
Never lose bots again, the AU3 method can run FUD Runtime for months and is 99.9% different each build.


INTERNAL LNK EXPLOIT BUILDER ->
*USE ANY ICON
*SPOOF ANY EXTENSTION
*USE DECOY
*OPTION TO AUTO OVERWRITE .LNK WITH THE DECOY ONCE FILE CLICKED
*OPTION TO CHANGE .LNK SIZE
*AUTO LNK OBFUSCATION
*COMPATIBLE WITH AU3 METHOD


INTERNAL VBS INSTALLER BUILDER (RECOMMENDED)->
*STEALTH AND UNDETECTED METHOD
*FAST & STABLE WITHOUT EXCEPTIONS
*COMPATIBLE WITH AU3 METHOD
*USE DECOY
*AUTO VBS OBFUSCATION
*OPTION TO AUTO OVERWRITE .VBS WITH THE DECOY ONCE FILE CLICKED
*CURRENTLY UNDETECTED BY MOST USED AVS AND ALMOST ALL AV

INTERNAL AU3+MSI BUILDER (THE MOST RECOMMENDED)
*STEALTH AND UNDETECTED , WORKING FAST AND STABLE FOR LONG TERM)
*WORKING VERY GOOD WITH (FAKE MSGBOX)
*SINGLE FILE
*CURRENTLY ITS OUR MOST UNDETECTED METHOD AND ITS EVADING ALL THE AVS (ATM)


INTERNAL CRYPTER ->
DarkGate including an internal crypter that using advanced techniques
There is 3 main crypting options that both of them currently FUD Runtime/Scantime by all the avs



STUB ->
Stub is 490kb(Uncompressed), coded in Borland Delphi 7 & Assembler, will work even in a very old Windows 2000 or XP since is coded from scratch
DarkGate (C&C) is fully coded in Embarcadero Delphi XE 10 x64
Some external stub modules, like the Miner, Miner injector and Reverse Proxy stub are coded in C++
Some external C&C modules, such as the ETC-Miner-Proxy and Reverse Proxy C&C are coded in C#
All data is fully encrypted and each bot has different encryption key pairs to avoid any kind of firewall detection


DARKGATE GLOBAL MANAGER
Global manager is an extension of DarkGate specially designed if you manage a large amount of bots

With that you can:
Change your domains/dns/ips at any time of all bots
Caption watchdog so you can know if some bot does something that you're intested on
Manage also your domains/dns/ips at any time of all bots of the Miner, you can use the same ones but you have the option to keep them separated
With that you can use different ports of the Loader for different operations, while having the control of all bots at any time also you can open an unlimited number of darkgate loader instances
This approach guarantees supporting an unlimited amount of bots and at least 60k online bots in each Loader port with a cheap server
It will host the LNK/VBS/MSI/AU3 decoy and payloads


Contact me in PM (Session, Matrix, or Signal) or Pidgin(OTR)
-> coding_guru@exploit.im
-> 09B950550CAD95899AC17C0B1384CD55C9BD81396B19EFFE2E80839D641D3221860ADEA89733


Runtime/scantime scan tests->

You can check runtime scan videos here ->

VBS METHOD

MSI METHOD


Checkzilla runtime scan ->
 
Последнее редактирование:
Пожалуйста, обратите внимание, что пользователь заблокирован
Пожалуйста, обратите внимание, что пользователь заблокирован
please leave reviews on - INTERNAL AU3+MSI BUILDER * ?
 
🤣..

CURRENT PRICES

Payments only in crypto (BTC, ETH, MONERO, ETC..)
1 DAY PACKAGE -> 1000$ (YOU CAN BUY THIS PACKAGE ONLY 1 TIME WITH EACH EXPLOIT.IN ACCOUNT)
MONTHLY - 15,000$
1 YEAR UPDATED -> 100,000$
 
Пожалуйста, обратите внимание, что пользователь заблокирован
Тот же самый, только там была одна из первых версий

🤣..

CURRENT PRICES

Payments only in crypto (BTC, ETH, MONERO, ETC..)
1 DAY PACKAGE -> 1000$ (YOU CAN BUY THIS PACKAGE ONLY 1 TIME WITH EACH EXPLOIT.IN ACCOUNT)
MONTHLY - 15,000$
1 YEAR UPDATED -> 100,000$
Что тут такого смешного? В экспе у меня 3.1337 БТС депозит
 
Пожалуйста, обратите внимание, что пользователь заблокирован
Продукт только для англоязычных ?
Почему? Мы радостно возьмем русско-говорящих людей перед англо. Только если ты имеешь ввиду есть-ли ру версии интерфейса, то пока-что нет. Но есть планы вставить ярлык под него, в не далекое время!
 
Пожалуйста, обратите внимание, что пользователь заблокирован
UPDATE

[+] Enhanced Loader Stability: Several internal changes to improve functionality.
The Loader is now capable of supporting up to 10,000 bots (70$/mo Server) by each port (up to 65535),
with a ping rate of once every 4 seconds.
If you require more capacity, you can simply tweak the ping configuration or launch additional DarkGate instances.
Moreover, DarkGate Global now has the ability to handle an unlimited number of simultaneous connections.

[+] Persistence Module:
In the event you discover and delete the files from the installation folder,
they are designed to automatically restore themselves. Plus another hidden startup method will stay in use.

[+] BSOD Protect:
If somehow the user/AV will find the installation folder and delete the files or the entire folder, not only will the files be restored,
but a system critical error will also occur. In addition, the files will be installed in an alternative location.
This feature operates without needing administrator privileges or any form of UAC bypass.

CONTACT (PM)
-> coding_guru@exploit.im
-> 09B950550CAD95899AC17C0B1384CD55C9BD81396B19EFFE2E80839D641D3221860ADEA89733
 
Пожалуйста, обратите внимание, что пользователь заблокирован
UPDATE

[!] Fixed: Keylogger not detecting keyboard on specific remote Windows Server systems
[!] Fixed: Persistence implementation had a detection at runtime
[!] Fixed: Rootkit injection was slow under certain conditions
[!] Added option to recalculate remote screen resolution if is not correctly scaled
[*] VBS Downloader do not wrap to .msi anymore
[*] Some internal tweaks

CONTACT (PM)
-> coding_guru@exploit.im
-> 09B950550CAD95899AC17C0B1384CD55C9BD81396B19EFFE2E80839D641D3221860ADEA89733
 
Пожалуйста, обратите внимание, что пользователь заблокирован
UPDATE

[*] Improved GUI error handler to assess bugs related to specific users
[!] Fixed Cookie recovery module on already running browser
[+] Added decoy option on vbs downloader
[+] You can sort creation & modified date in FileManager

CONTACT (PM)
-> coding_guru@exploit.im
-> 09B950550CAD95899AC17C0B1384CD55C9BD81396B19EFFE2E80839D641D3221860ADEA89733
 
Пожалуйста, обратите внимание, что пользователь заблокирован
Someone have try DarkGate ? as is to beautiful to be true . Please leave review.
On my Exploit.IN topic, the very first post/review is that of Quake3 the Moderator of Xss/Exploit. So you can take his words for it

review.PNG
 
Пожалуйста, обратите внимание, что пользователь заблокирован
UPDATE

[+] Binder added onto builder
[!] You can bind multiple files into your generated stub and select the mode it operates with command line support:
- Once Execute in memory
- Always Execute in memory
- Once Execute on disk
- Always Execute on disk
- Once Drop
- Always Drop

[+] Listen on Multiple ports (when opening darkgate, select a port range to allow multiple botnets in a single panel)
- You can specify 2351-2355 for example, and when you make a build you can mark an individual port to connect to

Contact (PM)

-> https://t.me/evtokens
-> coding_guru@exploit.im
-> 09B950550CAD95899AC17C0B1384CD55C9BD81396B19EFFE2E80839D641D3221860ADEA89733
 
Последнее редактирование:
Пожалуйста, обратите внимание, что пользователь заблокирован
UPDATE - AV Cleaning

[!] Bypass Sophos EDR + Sophos AV detection in au3 (main module)
[!] Updated au3 script apis morpher to fix detection by Kaspersky & Avast in vbs/msi
[!] Fixed Symantec & Avast detection in a few methods from PE Injection library
[*] Windows Defender NOT triggering any detections on delivery

Contact (PM)
-> https://t.me/evtokens
-> coding_guru@exploit.im
-> 09B950550CAD95899AC17C0B1384CD55C9BD81396B19EFFE2E80839D641D3221860ADEA89733
 
Пожалуйста, обратите внимание, что пользователь заблокирован
UPDATE

[*] Some internal tweaks to licensing system
[!] Some rare GUI bug fixes
[+] Improved internal stub error handler

Contact (PM)
-> https://t.me/evtokens
-> coding_guru@exploit.im
-> 09B950550CAD95899AC17C0B1384CD55C9BD81396B19EFFE2E80839D641D3221860ADEA89733
 
Пожалуйста, обратите внимание, что пользователь заблокирован
Статус
Закрыто для дальнейших ответов.
Верх