TGViewer
Zzz Stuff Zzz Stuff @zzzstuff · 162 subscribers
Post #214 240
Disclaimer: It's not meant for extracting keybox as of now. If you still dump secure region you might get the leaf certificates in plain text as mentioned in the screenshot but you won't get the EC private key in plain text. Try injecting a custom SVC into the functions that handle heavy math. You'll see some complex multiplication and addition continuously. If your device is older enough your TEE binary will have (armv7 and armv8) mixed codes and TAs loaded from vendor partition are also armv7. So patch accordingly. I can't say anything beyond this. Use it at your own risk. 

https://github.com/antagonizzzt/thalaivan

For those curious people. Here's the updated tool. You can start experimenting with this. Open the rmx2156 board file and include file to begin with. I've commented out how things work. I'm releasing this now. Becuz I won't be available for some days. 

 Also note that, ATF doesn't have a storage driver. So you have to rely on kaeru. Implement this into kaeru. Just call dump_call_smc(). A keypress or a custom fastboot command will do the job.

That's all for now
GitHub GitHub - antagonizzzt/thalaivan: A MediaTek ATF/TEE payload injector enabling arbitrary code execution at EL3 on vulnerable devices. A MediaTek ATF/TEE payload injector enabling arbitrary code execution at EL3 on vulnerable devices. - antagonizzzt/thalaivan
  • 🔥 3
More from @zzzstuff
  1. Jul 25, 2026document post
  2. Jul 8, 2026👀 next ec private key
  3. Jun 6, 2026Work in progress..
  4. Jan 12, 2026Introducing "thalaivan" - A PoC exploit that grants access to unrestricted EL3 code execut…
  5. Dec 13, 2025👀🩼
  6. Nov 9, 2025photo post
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →