Skip to content

Redirectors and Cover Stories

BaddKharma edited this page Sep 28, 2026 · 4 revisions

Redirectors and Cover Stories

A redirector is the front door of the attack side. It answers to the internet on a domain you own, decides what reaches the teamserver, and shows everyone else a cover site.

One front door, several backends

A fronts edge puts a redirector in front of a teamserver. One redirector can front several teamservers, each reached on its own URI path, so the operator picks a backend without changing the name.

Gating: beacon versus scanner

A request missing the validation header or the URI prefix is served the cover page rather than passed to the teamserver.

  • Leave the header value blank and the compiler rolls a fresh random one per build. A value shipped in a blueprint is a value everyone already has.
  • The same value reaches the teamserver through the fronts edge, so the C2 profile and the redirector cannot drift apart.
  • Known scanners, AV vendors, and TOR exits can be blocked. The bundled blocklist ships with the redirector role.

Certificates

TLS is from Let's Encrypt or self-signed.

Cover stories

Pick from twelve cover verticals: CDN, finance, healthcare, e-commerce, education, news, travel, sport, food, IT, a web server, and a maintenance page.

  • Each vertical is a whole site, not a splash screen: hero, services, testimonials, an address, a contact form, plus inner pages and a 404.
  • Each carries its own palette, brand, and copy, so two redirectors in one range share no fingerprint. Everything is invented, and the domain is always one you registered.
  • Photographs are fetched by the redirector at deploy time and served from its own docroot. The page makes no external request, and two redirectors on one vertical share no asset hash. Any slot left unfilled falls back to artwork drawn at build time.

Findings

  • RDR001 (error): the redirector has no domain, or the domain is still a placeholder. Supply one you control. See Deploying a Range.
  • RDR002 (warning): a cover knob is set that needs an asset pack (for example a hero video) but none was supplied. The page is fine and falls back; the canvas flags it so a knob that looks applied is not silently a no-op.

Clone this wiki locally