Kali Linux

Tor-Rootkit : A Python 3 Standalone Windows 10 / Linux Rootkit Using Tor

Tor-Rootkit is a Python 3 standalone Windows 10 / Linux Rootkit. The networking communication get’s established over the tor network.

How To Use

  • Clone the repo and change directory:

git clone https://github.com/emcruise/TorRootkit.git
cd ./tor-rootkit

Build docker container:

docker build -t listener .

Run docker container:

docker run -v $(pwd)/executables:/executables/ -it listener

Deploy the executables: When the listener is up and running it generates a “executables” directory containing different payloads for different plattforms.

TorRootkit/
│ …
└ executables/

Note: The client can take some time to connect because PyInstaller executables are a bit slower and it need’s to start tor.

Features

  • Standalone executables for Windows and Linux, including python interpreter and tor
  • the whole communication works over tor hidden services which guarantees some degree of anonymity
  • The Listener can handle multiple clients
  • The Listener generates payloads for different platforms on startup

Listener Shell Commands

CommandExplanation
helpShows the help menu
^C or exitExits the shell
listlists all connected clients with their according index
select <index>start shell with client

Client Shell Commands

CommandExplanation
helpShows the help menu
^C or exitExits the client shell and returns to listener shell
os <command>Executes a command in the clients shell and returns the output
backgroundKeeps the connection to a client and returns to listener

R K

Recent Posts

How UDP Works and Why It Is So Fast

When people ask how UDP works, the simplest answer is this: UDP sends data quickly…

21 hours ago

How EDR Killers Bypass Security Tools

Endpoint Detection and Response (EDR) solutions have become a cornerstone of modern cybersecurity, designed to…

4 days ago

AI-Generated Malware Campaign Scales Threats Through Vibe Coding Techniques

A large-scale malware campaign leveraging AI-assisted development techniques has been uncovered, revealing how attackers are…

4 days ago

How Does a Firewall Work Step by Step

How Does a Firewall Work Step by Step? What Is a Firewall and How Does…

5 days ago

Fake VPN Download Trap Can Steal Your Work Login in Minutes

People trying to securely connect to work are being tricked into doing the exact opposite.…

6 days ago

This Android Bug Can Crack Your Lock Screen in 60 Seconds

A newly disclosed Android vulnerability is making noise for a good reason. Researchers showed that…

1 week ago