Skip to content
Malware family Windows

Apollo

Apollo is an agent for the open-source Mythic command-and-control framework, most commonly recognized as a .NET implant focused on Windows post-exploitation.

Profile source: Mallory opens in a new tab

Apollo

Family profile

Apollo is an agent for the open-source Mythic command-and-control framework, most commonly recognized as a .NET implant focused on Windows post-exploitation. It is used to manage compromised hosts after initial access and has been observed both as a stock Mythic component and in customized forms used by threat actors. Public reporting also describes Apollo in broader Mythic contexts as a post-exploitation agent used to control compromised systems, but the strongest support ties Apollo specifically to the Windows .NET implementation.

Apollo provides operators with remote command execution and post-compromise control functions. Documented behavior includes execution of PowerShell commands and the ability to create and inject into processes such as Rundll32, making it suitable for in-memory execution and defense evasion during later intrusion stages. Reporting on Mythic usage also associates Apollo-enabled operations with credential dumping and lateral movement through auxiliary tooling integrated into the Mythic ecosystem.

Apollo has been observed in real-world intrusions by multiple actors. Customized Apollo implants were previously used by Stealth Falcon, an espionage-focused threat actor targeting government and defense entities in the Middle East and Africa, before the group transitioned to the more advanced Horus Agent. Apollo has also been identified in campaigns linked with interconnected pro-Ukrainian hacktivist clusters including 4BID and associated groups, where it appeared alongside other post-exploitation frameworks, remote-management tools, and ransomware in compromises of organizations across Russia, Belarus, Kazakhstan, the UAE, Syria, and Egypt.

Available reporting does not establish a unique initial delivery mechanism intrinsic to Apollo itself; instead, it is typically deployed after access has already been obtained through other means such as exploitation or phishing-delivered intrusion chains. Apollo is therefore best characterized as a Windows post-exploitation implant within Mythic rather than a standalone initial-access malware family.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Lateral Movement
  • Post Exploitation
  • Privilege Escalation
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 23, 2026
Last activity
Jul 23, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • US1

Leading providers

  • Cloudflare, Inc.1

Infrastructure traits

  • Anycast 1
  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
Mythic Likho

Название «Mythic» в имени кластера отражает использование Mythic C2 - открытого фреймворка для post-exploitation с множеством агентов (Apollo, Medusa, Athena).

Stealth Falcon

Named after the Egyptian falcon-headed sky god, Horus Agent represents an evolution from the group’s previously used customized Apollo implant.

Exploited software

Vulnerabilities linked to Apollo

1 CVEs

MITRE ATT&CK

Apollo in ATT&CK

8 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.