Last seven days
- First activity
- Jul 23, 2026
- Last activity
- Jul 23, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
Apollo is an agent for the open-source Mythic command-and-control framework, most commonly recognized as a .NET implant focused on Windows post-exploitation.
Profile source: Mallory opens in a new tabApollo
Apollo is an agent for the open-source Mythic command-and-control framework, most commonly recognized as a .NET implant focused on Windows post-exploitation. It is used to manage compromised hosts after initial access and has been observed both as a stock Mythic component and in customized forms used by threat actors. Public reporting also describes Apollo in broader Mythic contexts as a post-exploitation agent used to control compromised systems, but the strongest support ties Apollo specifically to the Windows .NET implementation.
Apollo provides operators with remote command execution and post-compromise control functions. Documented behavior includes execution of PowerShell commands and the ability to create and inject into processes such as Rundll32, making it suitable for in-memory execution and defense evasion during later intrusion stages. Reporting on Mythic usage also associates Apollo-enabled operations with credential dumping and lateral movement through auxiliary tooling integrated into the Mythic ecosystem.
Apollo has been observed in real-world intrusions by multiple actors. Customized Apollo implants were previously used by Stealth Falcon, an espionage-focused threat actor targeting government and defense entities in the Middle East and Africa, before the group transitioned to the more advanced Horus Agent. Apollo has also been identified in campaigns linked with interconnected pro-Ukrainian hacktivist clusters including 4BID and associated groups, where it appeared alongside other post-exploitation frameworks, remote-management tools, and ransomware in compromises of organizations across Russia, Belarus, Kazakhstan, the UAE, Syria, and Egypt.
Available reporting does not establish a unique initial delivery mechanism intrinsic to Apollo itself; instead, it is typically deployed after access has already been obtained through other means such as exploitation or phishing-delivered intrusion chains. Apollo is therefore best characterized as a Windows post-exploitation implant within Mythic rather than a standalone initial-access malware family.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
Название «Mythic» в имени кластера отражает использование Mythic C2 - открытого фреймворка для post-exploitation с множеством агентов (Apollo, Medusa, Athena).
Named after the Egyptian falcon-headed sky god, Horus Agent represents an evolution from the group’s previously used customized Apollo implant.
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.