Skip to content
Malware family

Adaptix C2

Adaptix C2 is a relatively new command-and-control/post-exploitation framework referenced as being adopted quickly by malicious actors.

Profile source: Mallory opens in a new tab

Adaptix C2

Family profile

Adaptix C2 is a relatively new command-and-control/post-exploitation framework referenced as being adopted quickly by malicious actors. In the provided reporting, it is described as command-and-control infrastructure used in Operation DUPEHIKE, a malware campaign dated December 5, 2025 that targeted Russian human resources personnel using a bonus-themed lure. That operation reportedly delivered the DUPERUNNER malware and involved process injection alongside use of Adaptix C2. Beyond its role as C2 infrastructure and its association with that campaign, the provided content does not supply further high-confidence technical details on Adaptix C2’s internal capabilities, supported platforms, protocols, or specific indicators of compromise.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 15, 2026
Last activity
Jul 22, 2026
Feed role
C2
Host form
64 IP / 1 hostnames

Leading locations

  • US28
  • HK7
  • CN5
  • NL5
  • BR2
  • FR2
  • JP2
  • PL2
  • SG2
  • AT1
  • CA1
  • DE1

Leading providers

  • HIVELOCITY, Inc.9
  • M247 Europe SRL7
  • FASTNET DATA INC3
  • Amazon.com, Inc.2
  • Hangzhou Alibaba Advertising Co.,Ltd.2
  • HostPapa2

Infrastructure traits

  • Hosting 61
  • Proxy 1

Samples

Recent associated samples

MITRE ATT&CK

Adaptix C2 in ATT&CK

3 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.