Skip to content

Adaptix C2

Adaptix C2 is a relatively new command-and-control/post-exploitation framework referenced as being adopted quickly by malicious actors.

Profile source: Mallory opens in a new tab

Adaptix C2

Family profile

Adaptix C2 is a relatively new command-and-control/post-exploitation framework referenced as being adopted quickly by malicious actors. In the provided reporting, it is described as command-and-control infrastructure used in Operation DUPEHIKE, a malware campaign dated December 5, 2025 that targeted Russian human resources personnel using a bonus-themed lure. That operation reportedly delivered the DUPERUNNER malware and involved process injection alongside use of Adaptix C2. Beyond its role as C2 infrastructure and its association with that campaign, the provided content does not supply further high-confidence technical details on Adaptix C2’s internal capabilities, supported platforms, protocols, or specific indicators of compromise.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 1, 2026
Last activity
Aug 7, 2026
Feed role
C2
Host form
43 IP / 2 hostnames

Leading locations

  • CN17
  • US4
  • FR3
  • HK3
  • MY3
  • CH2
  • JP2
  • NL2
  • RU2
  • AT1
  • BR1
  • DE1

Leading providers

  • Shenzhen Tencent Computer Systems Company Limited4
  • Cloudvalley Sdn. Bhd.3
  • CHINANET BACKBONE2
  • Hangzhou Alibaba Advertising Co.,Ltd.2
  • IDC, China Telecommunications Corporation2
  • ALEXHOST SRL1

Infrastructure traits

  • Hosting 37

Samples

Recent associated samples

MITRE ATT&CK

Adaptix C2 in ATT&CK

3 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.