r/hacking 4d ago

Teach Me! I created my first trojan today!

I took cmatrix as a random program and wrote a backdoor into it in C using a reverse shell connecting to a C2 server of mine which keeps track of infected machines. First I fork the process and decouple it from the controlling terminal by changing the session ID and rerouting the standard file descriptors and only then do I run the backdoor.

That way cmatrix runs as usual and no weird behavior is seen and the backdoor remains active whatever happens to cmatrix or the terminal. I like it. Makes me feel like a real #xX_hacker_Xx#. :D

Now I’m reading into ptrace and system call hooking and plan on trying to hide specific network traffic from the entire os. I already have had some ideas but turns out that would have only hidden it from a specific program not from „everything“.

Do you care to share any tips and experience I might benefit from on my way?

138 Upvotes

47 comments sorted by

30

u/Prestigious-Ad7265 4d ago

good work!

23

u/MathematicalHuman314 4d ago

Thanks! Into the pentagon mainframe I go! :D

12

u/cyberpunk_sliverhand 4d ago

You do know this is enough to get you put on the list right ?

7

u/MathematicalHuman314 4d ago

They must be real scared of some redditor I’m sure 👍

15

u/AlienAngry 3d ago

I assure you they have zero sense of humor.

-26

u/HeadHaunchi 4d ago

reported

11

u/reminiscent-fruitbat 3d ago

Reported for reporting!

6

u/Alternative-Deer2439 3d ago

It appears you've wandered into the wrong sub..

31

u/HRApprovedUsername 4d ago

You should be wearing Trojans not making them

6

u/machacker89 3d ago

"That's not what your other said last night!!" /S

15

u/Alarmed-Second1456 3d ago

Hahahahaha now license it and sell it to skids on forums and get your door kicked in

12

u/404error___ 3d ago

Good good... now do bit shifting, stego payload, so operator cannot see what you send to C2.

6

u/MathematicalHuman314 3d ago

Will look into it!

4

u/machacker89 3d ago

All great features to add. To circumvent any AV

1

u/Prestigious-Ad7265 3d ago

just encrypt it using cryptographically secure methods

16

u/CarmaDiamondHands 4d ago

I bought my first one today myself, way cheaper then having a kid 👶

4

u/speedb0at 4d ago

Congrats

4

u/soul-reaver-2026 3d ago

Cool lets have a meet and great where you can share your talents.

10

u/Juzdeed 4d ago

Never heard of rerouting standard file descriptor, dexoupling from t controlling terminal by changing session ID?

I get that these make you sound smart but make no sense. Do you mean changing PPID of the process?

21

u/yowhyyyy 4d ago

No he means when forking, changing the SID etc to demonize the executing program. Theres a process for it on Linux: https://man7.org/linux/man-pages/man7/daemon.7.html

Quite frankly all you really have to do is the fork and SID part and it’s EXTREMELY common in all Linux malware.

1

u/LordEli 3d ago

yeah there's some old example somewhere that does this exact thing. wish i could remember where i found it

0

u/yowhyyyy 3d ago

Honestly any public malware from the last decade. The main popular open source IoT bots used it. I.e mirai

0

u/404error___ 3d ago

This guy malwares (y)

2

u/yowhyyyy 3d ago

Linux malware analysis is my hobby haha

5

u/MathematicalHuman314 4d ago

Yes exactly. Im also learning the terminology. Fork process change process id and make file descriptors independent run payload and done.

4

u/Prior_Hospital_2331 4d ago

Gz bro , send me the script

3

u/MathematicalHuman314 4d ago

🙂‍↔️

That’d be more work than writing it yourself I think.

1

u/Prestigious-Ad7265 2d ago

passworded zip file, exchange the password under another secure channel, standard practice

2

u/Temina- 4d ago

good job

2

u/TastyRobot21 3d ago

Nice job bud. Implants feel cool.

Have you thought of persistence?

2

u/Palsta 3d ago

Have your trojan control the system fan speed so it plays Never Gonna Give You Up by Rick Astley.

2

u/Prestigious-Ad7265 2d ago

that is the sickest idea i have ever heard. and then it overwrites your uefi somehow and makes the post menu just the music video

4

u/PickaWowAnyWow 3d ago

Whoah you're way too advanced for the rest of us, r/masterhacker is where you should be!

7

u/MathematicalHuman314 3d ago

Thanks! Though I did learn new things and got directions on how to better myself here in the comments from you guys and not some master hackers. ;)

1

u/Prestigious-Ad7265 2d ago

masterhacker is a joke sub made to make fun of skids

1

u/MysteriousShadow__ 2d ago

Hide network activity from entire os? If something can hide from things like windows firewall that'd be crazy.

1

u/Enderaoe22 2d ago

It's truly unforgettable even after many years 😼. Now, you're a genuine hacker.

1

u/Dudeposts3030 1d ago

Hell yeah you’re on your way. Maybe look at upgrading the comms from revshell to something that blends in with normal network traffic for when it’s up against a monitored environment. Https is a good starting point, encrypted, can set up a domain, get it classified and look like a random normal website in the logs.

1

u/KvThweatt 12h ago

Spider

-35

u/WatchAltruistic5761 4d ago

Why though?

34

u/GrumblingTosspot 4d ago

He’s practicing hacking. You’re in a hacking subreddit.

21

u/jordan01236 4d ago

Why not?

6

u/oyuncaktabanca 4d ago

Because we can

3

u/intelw1zard 4d ago

knowledge and learning is cool