HomeSecurityAura Botnet, the botnet framework with C2 server based on Django

Aura Botnet, the botnet framework with C2 server based on Django

framework

Aura Botnet is an excellent portable botnet framework, with a C2 server based on Django. The client is written in C++, with alternate clients written in Rust, Bash, and Powershell.

The botnet's C2 server uses the Django framework as its backend. It is far from the most efficient web server, but it has features that make up for it:

  • Django is highly portable and therefore ideal for testing/educational purposes. The server and database are contained in the aura-server folder.
  • Django includes a very intuitive and powerful admin site that can be used to manage bots and commands
  • The server only handles simple POST requests
  • Static files must be served by a separate web server (local or remote) that specializes in serving static files, such as nginx.

The admin site located at http://your_server:server_port/admin, can be accessed after setting up a superuser.

Database

The C2 server is configured to use a SQLite3 database, bots.sqlite3. The current configuration can be changed in aura-server/aura/settings.py. You may want to use MySQL or even PostgreSQL, which is easy to do thanks to Django's portable API.

Bot clients

The base client is written in C++ and can be ported to Linux or Windows using CMake. Alternative clients are written in Rust, Bash, and Powershell, but may lack some of the functionality it provides, as they are not supported. They will fix any major bugs they discover, but some features will still be missing, such as running commands in different cells.

The client will gather relevant system information and send it to the C2 server to register the new bot. Authentication is done by first creating a file containing random data, which will be hushed every time the client runs, to identify it and validate the C2 server. It will then install all the files in the folder specified in the code and initialize the system service or schedule a task with the same permissions as the client was run with. The default settings “disguise” the client and other files as configuration files.

Because this is for testing purposes, the C2 server must be hard-coded into client and web, creating a temporary localhost in all files.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS