Giter Site home page Giter Site logo

cloud-malware-collection's Introduction

cloud-malware-collection

A collection of cloud malware & hacktools

AlienFoxGreenbotAndroxgh0st

A repository of interesting scripts related to AlienFox & Friends

What is AlienFox?

AlienFox is a label for a series of communally developed Python scripts that are used to attack improperly secured cloud services. These tools are based on the Androxgh0st code snippets found on GitHub.

The dominant themes I've seen is targeting of AWS and/or Laravel. These scripts aim to enable spamming on the victim's resources (cloud service, webserver).

Where did the name AlienFox originate?

Several of these scripts are explicitly named AlienFox. You can find the name AlienFox in the script name or internally declared in the script's ASCII art logo.

Predator

Files related to Predator AI, an actively maintained multipurpose cloud attack tool. Borrows components of Androxgh0st & AlienFox. The AI features are in beta. There may be an OpenAI API key in there. This tool requires a lot of hand holding to actually run, so reach out if you want help with that.

TeamTNT-Like

Several files from the 2023 TeamTNT-like campaign collecting credentials from AWS, Azure, & GCP.

Obligatory Disclaimer

These are cloud hack tools, dare I say CLOUD MALWARE! Please be careful and use them for research purposes--do no evil.

I did not write these scripts. I found them in code and malware repositories.

Research Suggestions

  • Analyze the reconnaissance mechanisms and check your assets/organization's exposure on these sites.
  • Build detections based on TTPs like the persistence & privilege escalation profiles or user account names (props to Permiso for this Androxgh0st tip).
  • If you want to find the authors, grep for "t.me" in these files. You will find author handles and distribution channels on Telegram.
  • Build these techniques into your red team ops. The configuration parsing scripts are particularly interesting from this standpoint. It may be less fruitful if your org doesn't use Laravel, but there are plenty of AF variants that parse other text-like configuration file types.

cloud-malware-collection's People

Contributors

emissaryspider avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.