Latest commit

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

1

EVILHack :: Social Engineering tool

A Python based Socail Engineering tool for QRL Jacking Whatsapp and Tiktok user accounts.


🔬 System Overview & Mechanism (QRLJacking)

EVILHack serves as a core technical demonstration of QRLJacking (Quick Response Code Login Jacking).

Many modern platforms (such as WhatsApp Web and TikTok) utilize QR codes as a primary method for quick, passwordless authentication. When a user scans a login QR code with their mobile app, the active session token is immediately bound to the web client.

How EVILHack Visualizes This Vector:

  1. Automated Initialization: The tool runs an automated background instance of Google Chrome using Selenium.
  2. Dynamic Extraction: Instead of taking focus-stealing system screenshots, EVILHack injects memory-level JavaScript loops (toDataURL) to capture raw image strings directly from the browser's active HTML5 Canvas memory pipeline.
  3. Local Hosting Matrix: A native background Python server captures this real-time data and streams it instantly to custom, external HTML templates (templates/index.html and templates/tiktok.html).
  4. Session Synchronization: The mirrored web panels allow developers to observe, test, and audit how live login matrix changes update dynamically across decoupled network networks.

User's can make or modify pre-existing templates according to there will and host the localhosted site for globall usage.

You can use cloudflare or localtonet (recommanded) to host the site on internet.


🛑 Legal & Security Disclaimer

WARNING: This tool is developed strictly for educational purposes, security research, authorized penetration testing, and defensive auditing.

Using EVILHack against targets without prior written authorization is illegal and violates computer fraud regulations. The author assumes zero liability for any misuse, damage, or legal consequences resulting from modifications or execution of this codebase. By downloading or running this software, you agree to use it exclusively in compliance with local security laws.


🛠️ Pre-Requisites & System Setup

Before executing the script, your host Linux system must have (recommanded) Google Chrome or Chromium installed on its global paths.

For Arch Linux:

sudo pacman -S google-chrome
# OR you can use yay 

For Ubuntu / Debian:

sudo apt update
sudo apt install google-chrome-stable

🚀 Installation & Execution

Follow these steps sequentially to deploy the platform environment inside an isolated Python virtual environment:

  1. Clone the Repository:

    git clone https://github.com/Unknownx007/Evilhack
    cd EvilHack
  2. Initialize and Activate Virtual Environment:

    python3 -m venv venv
    source venv/bin/activate
  3. Install Dependencies:

    pip install -r requirements.txt
  4. Launch the Engine Interface:

    python3 main.py
  5. Access the Synchronized Panels:

    • WhatsApp View:http://127.0.0.1
    • TikTok View:http://127.0.0.1

📝 License

Distributed under the MIT License.

MIT License<img width="757" height="306" alt="1" src="https://github.com/user-attachments/assets/ebb531a8-4a1e-4f4b-85f1-7355d64585df" />
Copyright (c) 2026 EVILHack Contributors
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

About

A python based Social Engineering QRL jacking framework that mirrors WhatsApp and TikTok session rendering contexts to a user customized based templates, local crimson web panels. Utilizes silent memory-level data hooks to ensure a stable jacking.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Latest commit

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

1

EVILHack :: Social Engineering tool

A Python based Socail Engineering tool for QRL Jacking Whatsapp and Tiktok user accounts.


🔬 System Overview & Mechanism (QRLJacking)

EVILHack serves as a core technical demonstration of QRLJacking (Quick Response Code Login Jacking).

Many modern platforms (such as WhatsApp Web and TikTok) utilize QR codes as a primary method for quick, passwordless authentication. When a user scans a login QR code with their mobile app, the active session token is immediately bound to the web client.

How EVILHack Visualizes This Vector:

  1. Automated Initialization: The tool runs an automated background instance of Google Chrome using Selenium.
  2. Dynamic Extraction: Instead of taking focus-stealing system screenshots, EVILHack injects memory-level JavaScript loops (toDataURL) to capture raw image strings directly from the browser's active HTML5 Canvas memory pipeline.
  3. Local Hosting Matrix: A native background Python server captures this real-time data and streams it instantly to custom, external HTML templates (templates/index.html and templates/tiktok.html).
  4. Session Synchronization: The mirrored web panels allow developers to observe, test, and audit how live login matrix changes update dynamically across decoupled network networks.

User's can make or modify pre-existing templates according to there will and host the localhosted site for globall usage.

You can use cloudflare or localtonet (recommanded) to host the site on internet.


🛑 Legal & Security Disclaimer

WARNING: This tool is developed strictly for educational purposes, security research, authorized penetration testing, and defensive auditing.

Using EVILHack against targets without prior written authorization is illegal and violates computer fraud regulations. The author assumes zero liability for any misuse, damage, or legal consequences resulting from modifications or execution of this codebase. By downloading or running this software, you agree to use it exclusively in compliance with local security laws.


🛠️ Pre-Requisites & System Setup

Before executing the script, your host Linux system must have (recommanded) Google Chrome or Chromium installed on its global paths.

For Arch Linux:

sudo pacman -S google-chrome
# OR you can use yay 

For Ubuntu / Debian:

sudo apt update
sudo apt install google-chrome-stable

🚀 Installation & Execution

Follow these steps sequentially to deploy the platform environment inside an isolated Python virtual environment:

  1. Clone the Repository:

    git clone https://github.com/Unknownx007/Evilhack
    cd EvilHack
  2. Initialize and Activate Virtual Environment:

    python3 -m venv venv
    source venv/bin/activate
  3. Install Dependencies:

    pip install -r requirements.txt
  4. Launch the Engine Interface:

    python3 main.py
  5. Access the Synchronized Panels:

    • WhatsApp View:http://127.0.0.1
    • TikTok View:http://127.0.0.1

📝 License

Distributed under the MIT License.

MIT License<img width="757" height="306" alt="1" src="https://github.com/user-attachments/assets/ebb531a8-4a1e-4f4b-85f1-7355d64585df" />
Copyright (c) 2026 EVILHack Contributors
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

About

A python based Social Engineering QRL jacking framework that mirrors WhatsApp and TikTok session rendering contexts to a user customized based templates, local crimson web panels. Utilizes silent memory-level data hooks to ensure a stable jacking.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

1

EVILHack :: Social Engineering tool

A Python based Socail Engineering tool for QRL Jacking Whatsapp and Tiktok user accounts.


🔬 System Overview & Mechanism (QRLJacking)

EVILHack serves as a core technical demonstration of QRLJacking (Quick Response Code Login Jacking).

Many modern platforms (such as WhatsApp Web and TikTok) utilize QR codes as a primary method for quick, passwordless authentication. When a user scans a login QR code with their mobile app, the active session token is immediately bound to the web client.

How EVILHack Visualizes This Vector:

  1. Automated Initialization: The tool runs an automated background instance of Google Chrome using Selenium.
  2. Dynamic Extraction: Instead of taking focus-stealing system screenshots, EVILHack injects memory-level JavaScript loops (toDataURL) to capture raw image strings directly from the browser's active HTML5 Canvas memory pipeline.
  3. Local Hosting Matrix: A native background Python server captures this real-time data and streams it instantly to custom, external HTML templates (templates/index.html and templates/tiktok.html).
  4. Session Synchronization: The mirrored web panels allow developers to observe, test, and audit how live login matrix changes update dynamically across decoupled network networks.

User's can make or modify pre-existing templates according to there will and host the localhosted site for globall usage.

You can use cloudflare or localtonet (recommanded) to host the site on internet.


🛑 Legal & Security Disclaimer

WARNING: This tool is developed strictly for educational purposes, security research, authorized penetration testing, and defensive auditing.

Using EVILHack against targets without prior written authorization is illegal and violates computer fraud regulations. The author assumes zero liability for any misuse, damage, or legal consequences resulting from modifications or execution of this codebase. By downloading or running this software, you agree to use it exclusively in compliance with local security laws.


🛠️ Pre-Requisites & System Setup

Before executing the script, your host Linux system must have (recommanded) Google Chrome or Chromium installed on its global paths.

For Arch Linux:

sudo pacman -S google-chrome
# OR you can use yay 

For Ubuntu / Debian:

sudo apt update
sudo apt install google-chrome-stable

🚀 Installation & Execution

Follow these steps sequentially to deploy the platform environment inside an isolated Python virtual environment:

  1. Clone the Repository:

    git clone https://github.com/Unknownx007/Evilhack
    cd EvilHack
  2. Initialize and Activate Virtual Environment:

    python3 -m venv venv
    source venv/bin/activate
  3. Install Dependencies:

    pip install -r requirements.txt
  4. Launch the Engine Interface:

    python3 main.py
  5. Access the Synchronized Panels:

    • WhatsApp View:http://127.0.0.1
    • TikTok View:http://127.0.0.1

📝 License

Distributed under the MIT License.

MIT License<img width="757" height="306" alt="1" src="https://github.com/user-attachments/assets/ebb531a8-4a1e-4f4b-85f1-7355d64585df" />
Copyright (c) 2026 EVILHack Contributors
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

About

A python based Social Engineering QRL jacking framework that mirrors WhatsApp and TikTok session rendering contexts to a user customized based templates, local crimson web panels. Utilizes silent memory-level data hooks to ensure a stable jacking.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

1

EVILHack :: Social Engineering tool

A Python based Socail Engineering tool for QRL Jacking Whatsapp and Tiktok user accounts.


🔬 System Overview & Mechanism (QRLJacking)

EVILHack serves as a core technical demonstration of QRLJacking (Quick Response Code Login Jacking).

Many modern platforms (such as WhatsApp Web and TikTok) utilize QR codes as a primary method for quick, passwordless authentication. When a user scans a login QR code with their mobile app, the active session token is immediately bound to the web client.

How EVILHack Visualizes This Vector:

  1. Automated Initialization: The tool runs an automated background instance of Google Chrome using Selenium.
  2. Dynamic Extraction: Instead of taking focus-stealing system screenshots, EVILHack injects memory-level JavaScript loops (toDataURL) to capture raw image strings directly from the browser's active HTML5 Canvas memory pipeline.
  3. Local Hosting Matrix: A native background Python server captures this real-time data and streams it instantly to custom, external HTML templates (templates/index.html and templates/tiktok.html).
  4. Session Synchronization: The mirrored web panels allow developers to observe, test, and audit how live login matrix changes update dynamically across decoupled network networks.

User's can make or modify pre-existing templates according to there will and host the localhosted site for globall usage.

You can use cloudflare or localtonet (recommanded) to host the site on internet.


🛑 Legal & Security Disclaimer

WARNING: This tool is developed strictly for educational purposes, security research, authorized penetration testing, and defensive auditing.

Using EVILHack against targets without prior written authorization is illegal and violates computer fraud regulations. The author assumes zero liability for any misuse, damage, or legal consequences resulting from modifications or execution of this codebase. By downloading or running this software, you agree to use it exclusively in compliance with local security laws.


🛠️ Pre-Requisites & System Setup

Before executing the script, your host Linux system must have (recommanded) Google Chrome or Chromium installed on its global paths.

For Arch Linux:

sudo pacman -S google-chrome
# OR you can use yay 

For Ubuntu / Debian:

sudo apt update
sudo apt install google-chrome-stable

🚀 Installation & Execution

Follow these steps sequentially to deploy the platform environment inside an isolated Python virtual environment:

  1. Clone the Repository:

    git clone https://github.com/Unknownx007/Evilhack
    cd EvilHack
  2. Initialize and Activate Virtual Environment:

    python3 -m venv venv
    source venv/bin/activate
  3. Install Dependencies:

    pip install -r requirements.txt
  4. Launch the Engine Interface:

    python3 main.py
  5. Access the Synchronized Panels:

    • WhatsApp View:http://127.0.0.1
    • TikTok View:http://127.0.0.1

📝 License

Distributed under the MIT License.

MIT License<img width="757" height="306" alt="1" src="https://github.com/user-attachments/assets/ebb531a8-4a1e-4f4b-85f1-7355d64585df" />
Copyright (c) 2026 EVILHack Contributors
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

About

A python based Social Engineering QRL jacking framework that mirrors WhatsApp and TikTok session rendering contexts to a user customized based templates, local crimson web panels. Utilizes silent memory-level data hooks to ensure a stable jacking.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Latest commit

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

1

EVILHack :: Social Engineering tool

A Python based Socail Engineering tool for QRL Jacking Whatsapp and Tiktok user accounts.


🔬 System Overview & Mechanism (QRLJacking)

EVILHack serves as a core technical demonstration of QRLJacking (Quick Response Code Login Jacking).

Many modern platforms (such as WhatsApp Web and TikTok) utilize QR codes as a primary method for quick, passwordless authentication. When a user scans a login QR code with their mobile app, the active session token is immediately bound to the web client.

How EVILHack Visualizes This Vector:

  1. Automated Initialization: The tool runs an automated background instance of Google Chrome using Selenium.
  2. Dynamic Extraction: Instead of taking focus-stealing system screenshots, EVILHack injects memory-level JavaScript loops (toDataURL) to capture raw image strings directly from the browser's active HTML5 Canvas memory pipeline.
  3. Local Hosting Matrix: A native background Python server captures this real-time data and streams it instantly to custom, external HTML templates (templates/index.html and templates/tiktok.html).
  4. Session Synchronization: The mirrored web panels allow developers to observe, test, and audit how live login matrix changes update dynamically across decoupled network networks.

User's can make or modify pre-existing templates according to there will and host the localhosted site for globall usage.

You can use cloudflare or localtonet (recommanded) to host the site on internet.


🛑 Legal & Security Disclaimer

WARNING: This tool is developed strictly for educational purposes, security research, authorized penetration testing, and defensive auditing.

Using EVILHack against targets without prior written authorization is illegal and violates computer fraud regulations. The author assumes zero liability for any misuse, damage, or legal consequences resulting from modifications or execution of this codebase. By downloading or running this software, you agree to use it exclusively in compliance with local security laws.


🛠️ Pre-Requisites & System Setup

Before executing the script, your host Linux system must have (recommanded) Google Chrome or Chromium installed on its global paths.

For Arch Linux:

sudo pacman -S google-chrome
# OR you can use yay 

For Ubuntu / Debian:

sudo apt update
sudo apt install google-chrome-stable

🚀 Installation & Execution

Follow these steps sequentially to deploy the platform environment inside an isolated Python virtual environment:

  1. Clone the Repository:

    git clone https://github.com/Unknownx007/Evilhack
    cd EvilHack
  2. Initialize and Activate Virtual Environment:

    python3 -m venv venv
    source venv/bin/activate
  3. Install Dependencies:

    pip install -r requirements.txt
  4. Launch the Engine Interface:

    python3 main.py
  5. Access the Synchronized Panels:

    • WhatsApp View:http://127.0.0.1
    • TikTok View:http://127.0.0.1

📝 License

Distributed under the MIT License.

MIT License<img width="757" height="306" alt="1" src="https://github.com/user-attachments/assets/ebb531a8-4a1e-4f4b-85f1-7355d64585df" />
Copyright (c) 2026 EVILHack Contributors
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

About

A python based Social Engineering QRL jacking framework that mirrors WhatsApp and TikTok session rendering contexts to a user customized based templates, local crimson web panels. Utilizes silent memory-level data hooks to ensure a stable jacking.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

1

EVILHack :: Social Engineering tool

A Python based Socail Engineering tool for QRL Jacking Whatsapp and Tiktok user accounts.


🔬 System Overview & Mechanism (QRLJacking)

EVILHack serves as a core technical demonstration of QRLJacking (Quick Response Code Login Jacking).

Many modern platforms (such as WhatsApp Web and TikTok) utilize QR codes as a primary method for quick, passwordless authentication. When a user scans a login QR code with their mobile app, the active session token is immediately bound to the web client.

How EVILHack Visualizes This Vector:

  1. Automated Initialization: The tool runs an automated background instance of Google Chrome using Selenium.
  2. Dynamic Extraction: Instead of taking focus-stealing system screenshots, EVILHack injects memory-level JavaScript loops (toDataURL) to capture raw image strings directly from the browser's active HTML5 Canvas memory pipeline.
  3. Local Hosting Matrix: A native background Python server captures this real-time data and streams it instantly to custom, external HTML templates (templates/index.html and templates/tiktok.html).
  4. Session Synchronization: The mirrored web panels allow developers to observe, test, and audit how live login matrix changes update dynamically across decoupled network networks.

User's can make or modify pre-existing templates according to there will and host the localhosted site for globall usage.

You can use cloudflare or localtonet (recommanded) to host the site on internet.


🛑 Legal & Security Disclaimer

WARNING: This tool is developed strictly for educational purposes, security research, authorized penetration testing, and defensive auditing.

Using EVILHack against targets without prior written authorization is illegal and violates computer fraud regulations. The author assumes zero liability for any misuse, damage, or legal consequences resulting from modifications or execution of this codebase. By downloading or running this software, you agree to use it exclusively in compliance with local security laws.


🛠️ Pre-Requisites & System Setup

Before executing the script, your host Linux system must have (recommanded) Google Chrome or Chromium installed on its global paths.

For Arch Linux:

sudo pacman -S google-chrome
# OR you can use yay 

For Ubuntu / Debian:

sudo apt update
sudo apt install google-chrome-stable

🚀 Installation & Execution

Follow these steps sequentially to deploy the platform environment inside an isolated Python virtual environment:

  1. Clone the Repository:

    git clone https://github.com/Unknownx007/Evilhack
    cd EvilHack
  2. Initialize and Activate Virtual Environment:

    python3 -m venv venv
    source venv/bin/activate
  3. Install Dependencies:

    pip install -r requirements.txt
  4. Launch the Engine Interface:

    python3 main.py
  5. Access the Synchronized Panels:

    • WhatsApp View:http://127.0.0.1
    • TikTok View:http://127.0.0.1

📝 License

Distributed under the MIT License.

MIT License<img width="757" height="306" alt="1" src="https://github.com/user-attachments/assets/ebb531a8-4a1e-4f4b-85f1-7355d64585df" />
Copyright (c) 2026 EVILHack Contributors
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

About

A python based Social Engineering QRL jacking framework that mirrors WhatsApp and TikTok session rendering contexts to a user customized based templates, local crimson web panels. Utilizes silent memory-level data hooks to ensure a stable jacking.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

1

EVILHack :: Social Engineering tool

A Python based Socail Engineering tool for QRL Jacking Whatsapp and Tiktok user accounts.


🔬 System Overview & Mechanism (QRLJacking)

EVILHack serves as a core technical demonstration of QRLJacking (Quick Response Code Login Jacking).

Many modern platforms (such as WhatsApp Web and TikTok) utilize QR codes as a primary method for quick, passwordless authentication. When a user scans a login QR code with their mobile app, the active session token is immediately bound to the web client.

How EVILHack Visualizes This Vector:

  1. Automated Initialization: The tool runs an automated background instance of Google Chrome using Selenium.
  2. Dynamic Extraction: Instead of taking focus-stealing system screenshots, EVILHack injects memory-level JavaScript loops (toDataURL) to capture raw image strings directly from the browser's active HTML5 Canvas memory pipeline.
  3. Local Hosting Matrix: A native background Python server captures this real-time data and streams it instantly to custom, external HTML templates (templates/index.html and templates/tiktok.html).
  4. Session Synchronization: The mirrored web panels allow developers to observe, test, and audit how live login matrix changes update dynamically across decoupled network networks.

User's can make or modify pre-existing templates according to there will and host the localhosted site for globall usage.

You can use cloudflare or localtonet (recommanded) to host the site on internet.


🛑 Legal & Security Disclaimer

WARNING: This tool is developed strictly for educational purposes, security research, authorized penetration testing, and defensive auditing.

Using EVILHack against targets without prior written authorization is illegal and violates computer fraud regulations. The author assumes zero liability for any misuse, damage, or legal consequences resulting from modifications or execution of this codebase. By downloading or running this software, you agree to use it exclusively in compliance with local security laws.


🛠️ Pre-Requisites & System Setup

Before executing the script, your host Linux system must have (recommanded) Google Chrome or Chromium installed on its global paths.

For Arch Linux:

sudo pacman -S google-chrome
# OR you can use yay 

For Ubuntu / Debian:

sudo apt update
sudo apt install google-chrome-stable

🚀 Installation & Execution

Follow these steps sequentially to deploy the platform environment inside an isolated Python virtual environment:

  1. Clone the Repository:

    git clone https://github.com/Unknownx007/Evilhack
    cd EvilHack
  2. Initialize and Activate Virtual Environment:

    python3 -m venv venv
    source venv/bin/activate
  3. Install Dependencies:

    pip install -r requirements.txt
  4. Launch the Engine Interface:

    python3 main.py
  5. Access the Synchronized Panels:

    • WhatsApp View:http://127.0.0.1
    • TikTok View:http://127.0.0.1

📝 License

Distributed under the MIT License.

MIT License<img width="757" height="306" alt="1" src="https://github.com/user-attachments/assets/ebb531a8-4a1e-4f4b-85f1-7355d64585df" />
Copyright (c) 2026 EVILHack Contributors
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

About

A python based Social Engineering QRL jacking framework that mirrors WhatsApp and TikTok session rendering contexts to a user customized based templates, local crimson web panels. Utilizes silent memory-level data hooks to ensure a stable jacking.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Latest commit

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

1

EVILHack :: Social Engineering tool

A Python based Socail Engineering tool for QRL Jacking Whatsapp and Tiktok user accounts.


🔬 System Overview & Mechanism (QRLJacking)

EVILHack serves as a core technical demonstration of QRLJacking (Quick Response Code Login Jacking).

Many modern platforms (such as WhatsApp Web and TikTok) utilize QR codes as a primary method for quick, passwordless authentication. When a user scans a login QR code with their mobile app, the active session token is immediately bound to the web client.

How EVILHack Visualizes This Vector:

  1. Automated Initialization: The tool runs an automated background instance of Google Chrome using Selenium.
  2. Dynamic Extraction: Instead of taking focus-stealing system screenshots, EVILHack injects memory-level JavaScript loops (toDataURL) to capture raw image strings directly from the browser's active HTML5 Canvas memory pipeline.
  3. Local Hosting Matrix: A native background Python server captures this real-time data and streams it instantly to custom, external HTML templates (templates/index.html and templates/tiktok.html).
  4. Session Synchronization: The mirrored web panels allow developers to observe, test, and audit how live login matrix changes update dynamically across decoupled network networks.

User's can make or modify pre-existing templates according to there will and host the localhosted site for globall usage.

You can use cloudflare or localtonet (recommanded) to host the site on internet.


🛑 Legal & Security Disclaimer

WARNING: This tool is developed strictly for educational purposes, security research, authorized penetration testing, and defensive auditing.

Using EVILHack against targets without prior written authorization is illegal and violates computer fraud regulations. The author assumes zero liability for any misuse, damage, or legal consequences resulting from modifications or execution of this codebase. By downloading or running this software, you agree to use it exclusively in compliance with local security laws.


🛠️ Pre-Requisites & System Setup

Before executing the script, your host Linux system must have (recommanded) Google Chrome or Chromium installed on its global paths.

For Arch Linux:

sudo pacman -S google-chrome
# OR you can use yay 

For Ubuntu / Debian:

sudo apt update
sudo apt install google-chrome-stable

🚀 Installation & Execution

Follow these steps sequentially to deploy the platform environment inside an isolated Python virtual environment:

  1. Clone the Repository:

    git clone https://github.com/Unknownx007/Evilhack
    cd EvilHack
  2. Initialize and Activate Virtual Environment:

    python3 -m venv venv
    source venv/bin/activate
  3. Install Dependencies:

    pip install -r requirements.txt
  4. Launch the Engine Interface:

    python3 main.py
  5. Access the Synchronized Panels:

    • WhatsApp View:http://127.0.0.1
    • TikTok View:http://127.0.0.1

📝 License

Distributed under the MIT License.

MIT License<img width="757" height="306" alt="1" src="https://github.com/user-attachments/assets/ebb531a8-4a1e-4f4b-85f1-7355d64585df" />
Copyright (c) 2026 EVILHack Contributors
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

About

A python based Social Engineering QRL jacking framework that mirrors WhatsApp and TikTok session rendering contexts to a user customized based templates, local crimson web panels. Utilizes silent memory-level data hooks to ensure a stable jacking.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages