macOS

Empire post-exploitation Framework Tool Restored – Compatible with Python 2/3

The Empire is a PowerShell framework that provides an ability to run the PowerShell agents without executing powershell.exe, it can be used to deploy post-exploitation modules and to evade detection.

One of the developers of the framework Chris Ross, announced earlier this year that tools were discontinued. He added that “The original objective of the Empire project was to demonstrate the post-exploitation capabilities of PowerShell and bring awareness to PowerShell attacks and we feel that we’ve accomplished that objective and are proud to see the security optics and improvements”

New Empire 3.0

BC security believes that the framework is still required, so they take the source of the framework and made significant changes. One of the most significant changes in the conversion from Python 2.7 to 3.x.

The release includes many new functionalities along with the functionalities with the Dev branch of the original Empire repository. Another notable improvement is the updated evasion capability by revoking the old components. The tool can be downloaded from GitHub.

“We have also updated the AMSI bypasses to reduce their size and change their signature. The Matt Graeber bypass is well known at this point and will cause Defender to flag on it without any obfuscation.”

Another notable feature is the Empire 3.0, includes the updated version of Mimikatz version 2.2.0, which allows attackers to launch an attack against Windows 10 machines.

“The update includes new feature is the addition of Data Protection API (DPAPI) support for Powershell PSCredential and SecureString.”

“We have implemented JA3/S randomization, but not JA3 randomization. The JA3 signature varies based on the listener used already, and unfortunately, to modify the signature typically requires Administrative privileges on the victim computer.”

BC security said that they continue to provide regular updates as new research is published, they have plans to incorporate C# modules into the framework, as well as other attack vectors, implementing function name aliasing and randomization, and adding a multi-user GUI.

Also Read: Free BlueKeep Detection Tool to Test Your Windows Machines for Against RDP Vulnerability

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago