Last seven days
- First activity
- Aug 27, 2026
- Last activity
- Sep 1, 2026
- Feed role
- C2
- Host form
- 8 IP / 0 hostnames
Havoc is an open-source command-and-control and post-exploitation framework created by C5pider and first released in 2022.
Profile source: Mallory opens in a new tabHavoc
Havoc is an open-source command-and-control and post-exploitation framework created by C5pider and first released in 2022. Its proprietary implant, called Demon, can be generated as an executable, DLL, or shellcode payload and communicates with team servers over HTTP(S) or SMB. Havoc supports operator-controlled beaconing, shell command execution, Beacon Object File execution, file and screenshot transfer, and configurable sleep-obfuscation methods. Demon payloads and Havoc-derived implants have also been observed using process injection, anti-analysis checks, credential theft, and endpoint-defense evasion, including AMSI/ETW tampering and BYOVD techniques in customized variants. Threat actors have deployed Havoc in espionage, critical-infrastructure, and financially motivated intrusions, including activity attributed or linked to Bitter, Transparent Tribe, Lemon Sandstorm, and suspected Russian-origin operators. Observed deployment chains include phishing-delivered archives and shortcut files, PowerShell execution, scheduled-task execution, custom loaders, and DLL side-loading. Havoc is principally used against Windows environments.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
CTU researchers observed a combination of these tools across intrusions... Havoc: acronis.exe, hwaudkiller.exe, sophos.exe, Sophos2.exe, Sophos3.exe.
Warcode (loader для Havoc, связующее звено со старым инструментарием APT36).
Variante Windows # Basée sur le framework Havoc avec des capacités post-exploitation personnalisées
This executes a Havoc payload. Created using domain administrator account. | The payload component was identified as a Havoc agent.
Proofpoint observed Bitter using KugelBlitz to deploy the Havoc C2 framework during hands-on activities.
in June, through the powershell loading havoc frame
The group has also used a DLL sideloading technique to launch the Havoc C2 post-exploitation framework, and establishes an SSH backdoor via AdaptixC2 or OpenSSH.
Havoc C2 for post-exploitation tasks like pivoting through compromised hosts into internal networks, privilege escalation, and maintaining stealth
The TrueChaos campaign has been found to weaponize this flaw in the update mechanism to likely deploy the open-source Havoc command-and-control (C2) framework to vulnerable endpoints.
What once ended with a $300 gift card purchase now ends with a modified Havoc C2 framework burrowed into your environment... deploying a mix of custom Havoc Demon payloads...
"...used to execute the Havoc command-and-control (C2) framework."
The attack is also characterized by the deployment of the Havoc post-exploitation framework on select systems...
OceanLotus: TahirSec has published a report on a recent OceanLotus (APT32) phishing campaign that drops Havoc payloads.
The final payload deployed as part of the attack is the open-source command-and-control (C2 or C&C) framework known as Havoc.
Lastly, some operators started experimenting with the Havoc C2 framework in March 2025, to supplement their tooling.
"...downloads and executes an additional payload, most commonly Havoc."
ShadowSyndicate continues to be associated with toolkits including Cobalt Strike, Metasploit, Havoc, Mythic, Sliver, AsyncRAT, MeshAgent, and Brute Ratel.
“The primary C2 frameworks observed were Cobalt Strike, VShell, Havoc, Sliver, and SparkRat.”
Nearly half a dozen organizations have been targeted with the Havoc command-and-control framework for subsequent data theft or ransomware compromise in a new IT support scam campaign.
This evolution includes the use of the Rust programming language, a departure from previous reliance on traditional compiled languages and frameworks like Cobalt Strike and Havoc.
"...borrowed adversary simulation frameworks such as Cobalt Strike, Havoc..." and "...components associated with the Havoc post-exploitation C2 framework... Havoc shellcode payload..."
"...borrowed adversary simulation frameworks such as Cobalt Strike, Havoc..." and "...components associated with the Havoc post-exploitation C2 framework... Havoc shellcode payload..."
Exploited software
MITRE ATT&CK
Reporting
NightmareEclipse released ShieldBreak, a proof-of-concept local privilege-escalation exploit claimed to bypass Microsoft’s fix for CVE-2026-50656 (RoguePlanet). The exploit allegedly abuses improper link resolution during Windows Defender remediation, combining Cloud Files placeholders, Object Manager symbolic-link swaps, CLFS path handling, an EICAR-triggered scan, and NTFS alternate data streams to redirect a Defender process running as SYSTEM and plant C:\Windows\System32\phoneinfo.dll. A fabricated Windows Error Reporting report and the QueueReporting scheduled task then cause wermgr.exe to load the malicious DLL; the included Warden.dll payload reportedly duplicates a SYSTEM token and opens a SYSTEM shell in the unprivileged user’s session. Splunk published attack data and multiple disabled-by-default analytics for the ShieldBreak chain, covering Defender activity on \globalroot\ object-manager paths (Defender Operational events 1116/1117), MpClient.dll loaded by non-Defender processes, ADS creation through loopback administrative SMB shares (Security event 5145), manually created .wer files in the Windows Error Reporting ReportQueue, creation of phantom DLLs such as phoneinfo.dll in system paths, and WerMgr.exe spawning SYSTEM-integrity children. Organizations should collect the required Sysmon, Security, and Defender Operational telemetry; enable file-share object-access auditing; investigate these signals promptly; and validate the creating process, signer, file hash, and operational need before suppressing alerts.
Researchers reported an active cyber espionage campaign linked with moderate confidence to APT36 (Transparent Tribe) that is targeting telecom, government, defense, energy, and other critical infrastructure organizations across South Asia, including lures tied to Afghan Telecom, government updates, and software installers. The operation uses a malware cluster that includes HACKERAI C2 Agent, PATCHCORD, and SHEETCORD, showing an evolution from earlier custom C/C++ tooling to newer Go-based implants. The malware uses legitimate cloud services as covert command-and-control channels, with HACKERAI abusing GitHub Gists and SHEETCORD using Google Sheets for command traffic and possible data exfiltration. Researchers said HACKERAI can gather system information, execute remote commands, and maintain persistence by modifying browser shortcuts while still opening the legitimate browser to avoid suspicion; published defensive leads include suspicious GitHub activity, altered browser shortcuts, malicious ZIP or installer files, and a set of reported IOCs including domains, an IP address, and multiple SHA-256 hashes.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.