Last seven days
- First activity
- Sep 2, 2026
- Last activity
- Sep 9, 2026
- Feed role
- C2 / Distribution
- Host form
- 26 IP / 2 hostnames
Adaptix C2 is a relatively new command-and-control/post-exploitation framework referenced as being adopted quickly by malicious actors.
Profile source: Mallory opens in a new tabAdaptix C2
Adaptix C2 is a relatively new command-and-control/post-exploitation framework referenced as being adopted quickly by malicious actors. In the provided reporting, it is described as command-and-control infrastructure used in Operation DUPEHIKE, a malware campaign dated December 5, 2025 that targeted Russian human resources personnel using a bonus-themed lure. That operation reportedly delivered the DUPERUNNER malware and involved process injection alongside use of Adaptix C2. Beyond its role as C2 infrastructure and its association with that campaign, the provided content does not supply further high-confidence technical details on Adaptix C2’s internal capabilities, supported platforms, protocols, or specific indicators of compromise.
C2 tracking
Derp observations, rolling seven-day window
Samples
45f00ef8a60cdc3332f809fa7e28404d1ab68d2f6e5a6e1f6458457e036e28cd 4ee37d13967642e0308eb4916060f8e699ceffd5420cf49b289da93245150ccf 5c49c90b6369772f7b52770beeb64ec0e2ad87b5c2c061ae840c2018d69e0c03 aa94d09edf94eb8a5ed05d638c6d5eebd4cc561ac61e274b86fd7abeb862f4a4 eef8e8fc4c87524003d818711ff20112f0d713fdcd16fa479672f4a95e823bc2 43c2df8d9d262beec1153288cf47d77a4a0a147f7b24197a9a29bdf662e51d96 6ee161bfddc7e54b395dd8d0ed6f806854e736502742a9ec1af4c0b82d44313e db6e16279fe4c6c21bfd6141f6f4f0d285242fd66238358aa92ec7bc9debc5e6 d2567486b387538ec3b462eefddbb152361453aee674ded29985e866c5a6c78b 6d63005c34a4575c58e6f17858b66e50ff234f01be19193eed93dd97141d796e MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.