WinSpy is a full-spectrum Windows RAT for red teams and security researchers. Hidden desktop, keylogger, persistent — all delivered through a Cloudflare tunnel with zero open ports.
Every module is configurable in the GUI builder. No source editing required.
A completely invisible Windows desktop runs in the background. Full mouse and keyboard passthrough with a live JPEG stream — the target's screen stays untouched, their cursor never moves.
Low-level SetWindowsHookEx (WH_KEYBOARD_LL) captures every keystroke — passwords, form fields, search queries. 500 KB ring buffer, auto-flush to controller. Special keys fully decoded.
Scheduled Task, Registry RunKey, or both simultaneously. Background watchdog detects removal attempts and re-registers within seconds. Survives reboots, sleep cycles, and log-offs.
Hardware execution breakpoint VEH — no code bytes written to any system DLL, no VirtualProtect calls, invisible to memory-integrity scans. Silences AmsiScanBuffer, EtwEventWrite, AmsiOpenSession, and EtwEventWriteFull in a single pass.
All traffic routes through Cloudflare — no open ports on the operator's machine, no static IP, TLS by default. Clients beacon to a Worker URL; the tunnel starts automatically on controller launch.
Built-in PyInstaller pipeline produces a single .exe. Configure process spoof name, PE metadata, marshal + zlib + XOR obfuscation, stealth mode, and persistence — all through a GUI.
Reads URL history from Chrome, Edge, Brave, and Opera History SQLite databases and Firefox's moz_places — last 150 visits per browser with title and visit count. Separate from the credential harvesting in Token Stealer; this is pure browsing history.
Full remote file system browser — upload, download, delete, execute. Paired with an interactive reverse CMD shell with persistent session and full colour output streamed live to the controller.
Live screen stream of the real visible desktop — separate from HVNC, this shows exactly what the user sees in real time. On-demand screenshots also available. Full resolution, JPEG-compressed, streamed directly to the controller panel.
Webcam streams live JPEG frames over WebSocket at 25 fps — rendered in the controller in real time. Microphone records a configurable number of seconds to WAV and delivers the file to the Downloads tab. Both run silently with no indicator light or system notification.
IP-based geolocation displayed on an interactive map in the controller. Country, city, ISP, and coordinates shown per client. WiFi access point scanning provides additional triangulation data where available, without any GPS access.
Full remote process list with PID, parent, image name, and path. Terminate any process on demand. Used to identify security tools running on the target before deploying modules or triggering evasion.
Worker process runs under a configurable system name — dllhost.exe, RuntimeBroker.exe, or any binary on the target. Paired with fake PE version info (FileDescription, CompanyName, OriginalFilename) to blend into process lists and AV telemetry.
Sandbox uptime threshold check, debugger detection via IsDebuggerPresent, VM presence fingerprinting, and sleep jitter. All toggleable in the builder — disable for targets where detection risk outweighs the sandbox exposure.
Deploys a fullscreen lockscreen overlay across every monitor simultaneously. Displays a custom operator-uploaded image as the ransom screen, blocks all keyboard shortcuts (Win+L, Win+D, Alt+Tab, Esc) and swallows every mouse event. The target is fully locked out. Released instantly with unransom from the controller.
Overwrites the Master Boot Record via direct disk access. Target machine fails to boot on next restart — no recovery without reinstall. Triggered remotely via a single command. Irreversible without external recovery media.
Harvests Discord auth tokens from all four Discord variants (stable, Canary, PTB, Development), saved login credentials from Chrome, Edge, Brave, Opera, Opera GX, and Vivaldi, DPAPI AES-256-GCM decrypted cookies from all Chromium profiles, Firefox saved logins and moz_cookies, and Telegram tdata folder detection. All returned in a single dump.
Background thread polls the clipboard every 0.8 seconds and logs every change with a timestamp — up to 200 entries. getclip dumps the full history in one call: passwords, URLs, wallet addresses, anything the user copied since the session started.
Attempts to request or bypass User Account Control elevation from the target machine. Configurable in the builder at compile time or triggerable live via req_admin. Required for MBR write access and certain persistence paths.
Fully removes all traces from the target on command — deletes the scheduled task, registry RunKey, installed binary, and worker process. The implode command leaves no artefacts for forensic recovery. Run before exiting an operation.
Contact us for pricing — we tailor access based on your use case.
All tiers come with setup assistance. Contact via Discord or Telegram.
Released June 2026
64-bit only. Tested against current public builds.