JXA Modules

Deploy a script that dynamically resolves various implant modules. Automatically resolve and install an HTTP C2 module. At runtime, tasks are sent to the agent which is able to resolve missing modules, install them, and run both shell and keyword-based TTPs.

Execute this chain

Download Operator (1.7.1)
Learn about Operator

TTPs

Grab a screenshot via API
Print working directory
Record room audio using microphone
Install a payload request module
Install and test a shell execution module
Discover weak Dylib loads with missing Dylibs
Run a subprocess with NSTask
Install a Hush current user plist persistence

Tags

apt29 scenario 1, apt29, surveillance