Assume that you want to transfer data from one machine to another machine. If you use public email services, FTP or any other protocols, you will be easily get caught by software implemented like DLP(Data loss prevention). So, here we can Exfiltrate data via monitor pixel color values(Monitor Screen as Convert channel).
Data Exfiltration Scenario: Attacker has windows 10 machine located in India and same machine with VMware console or VNC running with another windows 10 located in united states. Now assume a person from India wants to send data to united states.
Display protocols such as RDP are blocked, such that it is not possible to transfer files.Here we can use Screen Interfaces as Channel for data exfiltration.
Download the PTP RAT HERE
PTP-RAT is a proof-of-concept tool for exfiltrating data over screen interfaces, it encodes data in pixel color values and flashing the remote screen to send the exfiltrated data.Each screen flash starts with a header that allows data theft via the screen.
NOTE: Nyquist rate is the minimum rate at which a signal can be sampled without introducing errors.
NOTE: Flashing with gray screen denotes that sampling of a signal in progress.
Must Read Complete Kali Tools tutorials from Information gathering to Forensics
PTP-RAT shows extreme bypass to implemented controls ( Hardware & Software Security Appliances).
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.
A groundbreaking technique for Kerberos relaying over HTTP, leveraging multicast poisoning, has been recently detailed…
Since mid-2024, cybersecurity researchers have been monitoring a sophisticated Android malware campaign dubbed "Tria Stealer,"…
Proton, the globally recognized provider of privacy-focused services such as Proton VPN and Proton Pass,…
The cybersecurity landscape faces increasing challenges as Arcus Media ransomware emerges as a highly sophisticated…
Proofpoint researchers have identified a marked increase in phishing campaigns and malicious domain registrations designed…
A recent investigation by Unit 42 of Palo Alto Networks has uncovered a sophisticated, state-sponsored…