
Aura Botnet is an excellent portable botnet framework, with a C2 server based on Django. The client is written in C++, with alternate clients written in Rust, Bash, and Powershell.
The botnet's C2 server uses the Django framework as its backend. It is far from the most efficient web server, but it has features that make up for it:
- Django is highly portable and therefore ideal for testing/educational purposes. The server and database are contained in the aura-server folder.
- Django includes a very intuitive and powerful admin site that can be used to manage bots and commands
- The server only handles simple POST requests
- Static files must be served by a separate web server (local or remote) that specializes in serving static files, such as nginx.
The admin site located at http://your_server:server_port/admin, can be accessed after setting up a superuser.
Database
The C2 server is configured to use a SQLite3 database, bots.sqlite3. The current configuration can be changed in aura-server/aura/settings.py. You may want to use MySQL or even PostgreSQL, which is easy to do thanks to Django's portable API.
Bot clients
The base client is written in C++ and can be ported to Linux or Windows using CMake. Alternative clients are written in Rust, Bash, and Powershell, but may lack some of the functionality it provides, as they are not supported. They will fix any major bugs they discover, but some features will still be missing, such as running commands in different cells.
The client will gather relevant system information and send it to the C2 server to register the new bot. Authentication is done by first creating a file containing random data, which will be hushed every time the client runs, to identify it and validate the C2 server. It will then install all the files in the folder specified in the code and initialize the system service or schedule a task with the same permissions as the client was run with. The default settings “disguise” the client and other files as configuration files.
Because this is for testing purposes, the C2 server must be hard-coded into client and web, creating a temporary localhost in all files.
