Skip to content

Apollo

Apollo is an open-source post-exploitation agent used with the Mythic command-and-control framework.

Profile source: Mallory opens in a new tab

Apollo

Family profile

Apollo is an open-source post-exploitation agent used with the Mythic command-and-control framework. It is most commonly recognized as the .NET Mythic agent focused on Windows, although some references describe it more broadly within Mythic’s multi-agent ecosystem. Apollo is designed for managing compromised hosts after initial access and supports operator tasking through Mythic infrastructure.

Documented Apollo functionality includes command execution, execution of PowerShell commands, and process creation and injection behavior, including default support for creating and injecting into Rundll32. Reporting also associates Apollo with credential-dumping workflows through Mythic operator tradecraft, including use alongside tools such as Mimikatz for credential access and lateral movement. These characteristics place Apollo firmly in the post-exploitation phase rather than as a standalone initial-access tool.

Apollo has been observed both as a stock Mythic agent and in customized forms used by threat actors. Stealth Falcon used customized Apollo implants prior to transitioning to the more advanced Horus Agent, which is assessed as an evolution of that earlier Apollo-based tooling. Apollo has also been observed in campaigns linked with pro-Ukrainian hacktivist and intrusion clusters alongside other frameworks such as Sliver, Havoc, and AdaptixC2, indicating its use as one component in broader intrusion operations.

Operationally, Apollo is relevant to espionage and hands-on-keyboard intrusions because it provides flexible remote control of Windows systems and integrates into the broader Mythic ecosystem of agents and transports. Detection efforts have specifically targeted Apollo through YARA and behavioral signatures tied to Mythic C2 communication patterns and .NET Apollo agent structures.

Capabilities

  • Credential Theft
  • Lateral Movement
  • Post Exploitation
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 3, 2026
Last activity
Sep 8, 2026
Feed role
C2 / Distribution
Host form
10 IP / 4 hostnames

Leading locations

  • DE4
  • US3
  • NL2
  • CN1
  • GB1
  • KR1
  • RU1
  • TR1

Leading providers

  • Omegatech LTD3
  • China Telecom Beijing Tianjin Hebei Big Data Industry Park Branch1
  • Cloudflare, Inc.1
  • DEFT.COM1
  • FEMO IT SOLUTIONS LIMITED1
  • JSC TIMEWEB1

Infrastructure traits

  • Hosting 11
  • Anycast 1

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
Mythic Likho

Название «Mythic» в имени кластера отражает использование Mythic C2 - открытого фреймворка для post-exploitation с множеством агентов (Apollo, Medusa, Athena).

Stealth Falcon

Named after the Egyptian falcon-headed sky god, Horus Agent represents an evolution from the group’s previously used customized Apollo implant.

Exploited software

Vulnerabilities linked to Apollo

1 CVEs

MITRE ATT&CK

Apollo in ATT&CK

8 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.