screetsec / TheFatRat

Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This tool compiles a malware with popular payload and then the compiled malware can be execute on windows, android, mac . The malware that created with this tool also have an ability to bypass most AV software protection .
GNU General Public License v3.0
9.5k stars 2.27k forks source link

Antivirus #788

Open Roxter8 opened 1 year ago

Roxter8 commented 1 year ago

Hello, i'm creating backdoor using MSFVenom [1], then, in another terminal i'm starting msfvenom, and set port and Lhost, but when i'm checking it for AntiVirus, Every Antivirus can detect it, so what i should do?

Morsmalleo commented 1 year ago

There are several other payload options in TheFatRat, one that I found successful for evading AV, was payloads built with Powerstager I think it was, give that a try

It's been a while since I've tested since then however.

Morsmalleo commented 1 year ago

Hello, i'm creating backdoor using MSFVenom [1], then, in another terminal i'm starting msfvenom, and set port and Lhost, but when i'm checking it for AntiVirus, Every Antivirus can detect it, so what i should do?

You can also blame the idiots that call themselves "Computer professionals" when they're just script kiddies or kids creating GitHub accounts to use TheFatRat, who uploaded the files created by the tool to Virustotal when they were explicitly told not to both by the Dev and by the tool itself, for the every file generated being detected by AV.

Roxter8 commented 1 year ago

Hello, i'm creating backdoor using MSFVenom [1], then, in another terminal i'm starting msfvenom, and set port and Lhost, but when i'm checking it for AntiVirus, Every Antivirus can detect it, so what i should do?

You can also blame the idiots that call themselves "Computer professionals" when they're just script kiddies or kids creating GitHub accounts to use TheFatRat, who uploaded the files created by the tool to Virustotal when they were explicitly told not to both by the Dev and by the tool itself, for the every file generated being detected by AV.

I know about Virustoral, i'm full time Java developer, i just want to learn about cybersecurity. I wrote my own payload and it's worked