Last seven days
- First activity
- Sep 3, 2026
- Last activity
- Sep 8, 2026
- Feed role
- C2 / Distribution
- Host form
- 10 IP / 4 hostnames
Apollo is an open-source post-exploitation agent used with the Mythic command-and-control framework.
Profile source: Mallory opens in a new tabApollo
Apollo is an open-source post-exploitation agent used with the Mythic command-and-control framework. It is most commonly recognized as the .NET Mythic agent focused on Windows, although some references describe it more broadly within Mythic’s multi-agent ecosystem. Apollo is designed for managing compromised hosts after initial access and supports operator tasking through Mythic infrastructure.
Documented Apollo functionality includes command execution, execution of PowerShell commands, and process creation and injection behavior, including default support for creating and injecting into Rundll32. Reporting also associates Apollo with credential-dumping workflows through Mythic operator tradecraft, including use alongside tools such as Mimikatz for credential access and lateral movement. These characteristics place Apollo firmly in the post-exploitation phase rather than as a standalone initial-access tool.
Apollo has been observed both as a stock Mythic agent and in customized forms used by threat actors. Stealth Falcon used customized Apollo implants prior to transitioning to the more advanced Horus Agent, which is assessed as an evolution of that earlier Apollo-based tooling. Apollo has also been observed in campaigns linked with pro-Ukrainian hacktivist and intrusion clusters alongside other frameworks such as Sliver, Havoc, and AdaptixC2, indicating its use as one component in broader intrusion operations.
Operationally, Apollo is relevant to espionage and hands-on-keyboard intrusions because it provides flexible remote control of Windows systems and integrates into the broader Mythic ecosystem of agents and transports. Detection efforts have specifically targeted Apollo through YARA and behavioral signatures tied to Mythic C2 communication patterns and .NET Apollo agent structures.
C2 tracking
Derp observations, rolling seven-day window
Samples
2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 3087da9b2811b257d9f5fb3780adcbb3f5813c4e15d9f2e87e1002f86fe5f682 4757b008f984a79a393d6838a0482e71623ed763af65d9fc1ced963caeea64ca 902bea9e4aeeed4e0b5d30a9cbcc6f9f1fc687b79c3fdde8258b94b410d1797a bf258d449b89e60adde308adb9e1204e4b8052894f0cfaf1fb83ea2904de89dc 1b723594e574c00aac2c946ff738a0454f7c24f6ebc84ae45a6af9628b08cb96 40b643468356c0fd751893647ad0dc9e2a0019427e4f5f0e2f6e559efcecb977 508e710d673802a532798e7dffa3aefcfb36eff0acef1620b8614917ac62e53e 9f0a4fce6d13c892326cf6788258b035118901d2551e43cc214083acc7ff2a24 e72b03d7ce71ec92460622726d6bc55228eb8a62d39e82d8749f45fe497ba35c Reported operators
Название «Mythic» в имени кластера отражает использование Mythic C2 - открытого фреймворка для post-exploitation с множеством агентов (Apollo, Medusa, Athena).
Named after the Egyptian falcon-headed sky god, Horus Agent represents an evolution from the group’s previously used customized Apollo implant.
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.