Source code and details: https://github.com/umutcamliyurt/TyphonRAT

Legal Disclaimer:

This project is provided for educational, research, and authorized security testing purposes only. Use of this software against systems, networks, or devices without explicit permission is illegal and unethical. The author assumes no responsibility or liability for any misuse, damage, or legal consequences resulting from the use of this software.

Description:

TyphonRAT avoids detection by embedding authentication in standard HTTP headers, blending C&C traffic with normal API requests. With TLS encryption, decoy webpage server and SNI spoofing, it evades IDS, firewalls and monitoring tools by mimicking legitimate traffic.

Features:

  • Undetectable by most firewall & IDS solutions

  • Single listener port that routes clients to the C&C and regular traffic to a proxy target

  • Client is written in C for maximum portability

  • Certificate pinning using SHA-256 hash