Windows Trojan & Reverse-Shell Generator Tool
AV/AMSI evasion
TRON is a hacking tool designed to deploy Windows reverse cmd, PowerShell, and Meterpreter shells utilizing AMSI and AV evasion techniques.
Originally developed for internal penetration tests, TRON was built to reliably bypass antivirus controls and establish reverse shells during authorized assessments. TwelveSec recently recovered this tool from their archives and is publishing it for the security community to use for research, education, and fun.β€οΈ
- Added: Non-root execution support (root privileges are no longer required to run the tool).
- Added: Internet connectivity check. (Rust payload compilation requires an active connection, so the tool now verifies this before proceeding).
- Changed: Made
apache2andxclipoptional dependencies, as they are not strictly required for core execution. - Fixed: General bug fixes and stability improvements.
git clone https://github.com/twelvesec/TRON.git
sudo ln -s $(pwd)/TRON/tron /usr/bin/
sudo tron
TRON currently supports the following platforms:
- Kali Linux (ARM64 & AMD64)
- Debian
- Parrot OS
TRON provides several shell-generation and execution techniques.
0. Simple PowerShell shell (stageless)
1. Simple CMD shell (staged)
2. Meterpreter reverse_https shell (staged)
3. Meterpreter reverse_tcp shell (staged)
4. Meterpreter encrypted reverse_tcp shell (encrypted_staged)
5. Meterpreter win_https shell (staged)
6. Simple CMD command executor
7. Meterpreter reverse_https shell (Under Development)
Test date: 23/09/2026
TRON was tested against a fully updated Windows 11 installation with Microsoft Defender enabled.
compressed_video.mp4
π We strongly encourage the community to test TRON against various AV solutions across different environments. Feel free to share your testing results, report bugs, or open issues on GitHub or social media so we can continue updating and improving the tool.
The generated executable expects to retrieve the required PowerShell components and payload-related files from an HTTP server.
The current implementation expects the HTTP server to listen on:
TCP/80
The server should serve the directory containing the generated files.
For example:
sudo python3 -m http.server 80TRON utilizes a staged delivery architecture that requires two open ports on the operator's machine:
- HTTP Server (Port 80): Serves the necessary staging files and decryption keys.
- Reverse Shell Listener (Custom Port): Catches the incoming connection from the executed payload.
When the generated executable is run on the target machine, it reaches out to the operator's HTTP server and downloads three specific files:
- A PowerShell script that crashes AMSI.
- A PowerShell script containing the encrypted reverse shell payload.
- A text file containing the exact passphrase required for decryption.
Once downloaded, the payload is decrypted in memory and executed, establishing a reverse shell connection back to the operator's listening port.
βββββββββββββββββββββββββββββββββββββββββββ
β Attacker Infrastructure β
β β
β ββββββββββββββββ βββββββββββββββ β
β β HTTP Server β β Listener β β
β β (TCP/80) β β (Custom TCP)β β
β ββββββββ¬ββββββββ ββββββββ²βββββββ β
βββββββββββΌββββββββββββββββββββββΌββββββββββ
β β
1. Executable requests staging files β 3. Decrypted payload
β β connects back
βΌ β
βββββββββββ΄ββββββββββββββββββββββΌββββββββββ
β Target Machine β β
β β β
β 2. Downloads: β β
β βββ Amsi Crasher PS Script β β
β βββ Encrypted PS Payload β β
β βββ Decryption Key File β β
β β β
βββββββββββββββββββββββββββββββββ΄ββββββββββ
- Implement a ZIP packer option for payloads.
- Implement an ISO packer option for payloads.
- Develop new undetectable (FUD) Meterpreter evasion techniques.
- To support Mac
TRON was originally created by Aristos for internal penetration-testing activities. The project was subsequently recovered from an archive and released by TwelveSec for the security community.
Made by Aristos with Love β₯
Only use TRON against systems for which you have explicit authorization. The authors and contributors are not responsible for unauthorized use, damage, or other consequences resulting from the use of this software.
TRON is released under the MIT license. See LICENSE for details.