Skip to content

Havoc

Havoc is an open-source command-and-control and post-exploitation framework created by C5pider and first released in 2022.

Profile source: Mallory opens in a new tab

Havoc

Family profile

Havoc is an open-source command-and-control and post-exploitation framework created by C5pider and first released in 2022. Its proprietary implant, called Demon, can be generated as an executable, DLL, or shellcode payload and communicates with team servers over HTTP(S) or SMB. Havoc supports operator-controlled beaconing, shell command execution, Beacon Object File execution, file and screenshot transfer, and configurable sleep-obfuscation methods. Demon payloads and Havoc-derived implants have also been observed using process injection, anti-analysis checks, credential theft, and endpoint-defense evasion, including AMSI/ETW tampering and BYOVD techniques in customized variants. Threat actors have deployed Havoc in espionage, critical-infrastructure, and financially motivated intrusions, including activity attributed or linked to Bitter, Transparent Tribe, Lemon Sandstorm, and suspected Russian-origin operators. Observed deployment chains include phishing-delivered archives and shortcut files, PowerShell execution, scheduled-task execution, custom loaders, and DLL side-loading. Havoc is principally used against Windows environments.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Post Exploitation
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 27, 2026
Last activity
Sep 1, 2026
Feed role
C2
Host form
8 IP / 0 hostnames

Leading locations

  • CN2
  • BR1
  • HK1
  • LV1
  • RU1
  • SA1
  • US1

Leading providers

  • DigitalOcean, LLC1
  • EDIS GmbH1
  • Hangzhou Alibaba Advertising Co.,Ltd.1
  • Locaweb Serviços de Internet S/A1
  • NetLab Global1
  • Saudi Telecom Company JSC1

Infrastructure traits

  • Hosting 6

Reported operators

Threat actors

22 named in public reporting
GOLD SHERWOOD

CTU researchers observed a combination of these tools across intrusions... Havoc: acronis.exe, hwaudkiller.exe, sophos.exe, Sophos2.exe, Sophos3.exe.

Transparent Tribe

Warcode (loader для Havoc, связующее звено со старым инструментарием APT36).

UAT-10147

Variante Windows # Basée sur le framework Havoc avec des capacités post-exploitation personnalisées

Fox Kitten

This executes a Havoc payload. Created using domain administrator account. | The payload component was identified as a Havoc agent.

Bitter

Proofpoint observed Bitter using KugelBlitz to deploy the Havoc C2 framework during hands-on activities.

APT Q 37

in June, through the powershell loading havoc frame

GOLD ENCOUNTER

The group has also used a DLL sideloading technique to launch the Havoc C2 post-exploitation framework, and establishes an SSH backdoor via AdaptixC2 or OpenSSH.

TeamPCP

Havoc C2 for post-exploitation tasks like pivoting through compromised hosts into internal networks, privilege escalation, and maintaining stealth

Amaranth-Dragon

The TrueChaos campaign has been found to weaponize this flaw in the update mechanism to likely deploy the open-source Havoc command-and-control (C2) framework to vulnerable endpoints.

FIN7

What once ended with a $300 gift card purchase now ends with a modified Havoc C2 framework burrowed into your environment... deploying a mix of custom Havoc Demon payloads...

KTA440

"...used to execute the Havoc command-and-control (C2) framework."

BRONZE BUTLER

The attack is also characterized by the deployment of the Havoc post-exploitation framework on select systems...

APT32

OceanLotus: TahirSec has published a report on a recent OceanLotus (APT32) phishing campaign that drops Havoc payloads.

APT41

The final payload deployed as part of the attack is the open-source command-and-control (C2 or C&C) framework known as Havoc.

Hydra Saiga

Lastly, some operators started experimenting with the Havoc C2 framework in March 2025, to supplement their tooling.

Molerats

"...downloads and executes an additional payload, most commonly Havoc."

ShadowSyndicate

ShadowSyndicate continues to be associated with toolkits including Cobalt Strike, Metasploit, Havoc, Mythic, Sliver, AsyncRAT, MeshAgent, and Brute Ratel.

TGR-STA-1030

“The primary C2 frameworks observed were Cobalt Strike, VShell, Havoc, Sliver, and SparkRat.”

Black Basta

Nearly half a dozen organizations have been targeted with the Havoc command-and-control framework for subsequent data theft or ransomware compromise in a new IT support scam campaign.

SloppyLemming

This evolution includes the use of the Rust programming language, a departure from previous reliance on traditional compiled languages and frameworks like Cobalt Strike and Havoc.

Fishing Elephant

"...borrowed adversary simulation frameworks such as Cobalt Strike, Havoc..." and "...components associated with the Havoc post-exploitation C2 framework... Havoc shellcode payload..."

Outrider Tiger

"...borrowed adversary simulation frameworks such as Cobalt Strike, Havoc..." and "...components associated with the Havoc post-exploitation C2 framework... Havoc shellcode payload..."

Exploited software

Vulnerabilities linked to Havoc

3 CVEs

MITRE ATT&CK

Havoc in ATT&CK

90 distinct techniques

Techniques

90 techniques
T1562.001 Disable or Modify Tools T1211 Exploitation for Defense Evasion T1001.003 Protocol or Service Impersonation T1583.003 Virtual Private Server T1090.002 External Proxy T1071.001 Web Protocols T1583.006 Web Services T1090.003 Multi-hop Proxy T1588.002 Tool T1053.005 Scheduled Task T1497 Virtualization/Sandbox Evasion T1562 Impair Defenses T1573 Encrypted Channel T1620 Reflective Code Loading T1059.001 PowerShell T1070.004 File Deletion T1071 Application Layer Protocol T1090 Proxy T1036 Masquerading T1055 Process Injection T1059.003 Windows Command Shell T1071.002 File Transfer Protocols T1202 Indirect Command Execution T1204.002 Malicious File T1055.002 Portable Executable Injection T1106 Native API T1566.001 Spearphishing Attachment T1027.007 Dynamic API Resolution T1140 Deobfuscate/Decode Files or Information T1033 System Owner/User Discovery T1543.003 Windows Service T1105 Ingress Tool Transfer T1218 System Binary Proxy Execution T1059 Command and Scripting Interpreter T1566 Phishing T1656 Impersonation T1027 Obfuscated Files or Information T1595 Active Scanning T1590 Gather Victim Network Information T1190 Exploit Public-Facing Application T1548.002 Bypass User Account Control T1598 Phishing for Information T1068 Exploitation for Privilege Escalation T1574.001 DLL T1543.001 Launch Agent T1059.005 Visual Basic T1133 External Remote Services T1018 Remote System Discovery T1505.003 Web Shell T1021.002 SMB/Windows Admin Shares T1218.011 Rundll32 T1047 Windows Management Instrumentation T1518.001 Security Software Discovery T1041 Exfiltration Over C2 Channel T1027.013 Encrypted/Encoded File T1036.001 Invalid Code Signature T1037.001 Logon Script (Windows) T1566.002 Spearphishing Link T1218.007 Msiexec T1036.005 Match Legitimate Resource Name or Location T1057 Process Discovery T1219 Remote Access Tools T1082 System Information Discovery T1195.001 Compromise Software Dependencies and Development Tools T1112 Modify Registry T1195 Supply Chain Compromise T1204 User Execution T1203 Exploitation for Client Execution T1189 Drive-by Compromise T1113 Screen Capture T1497.003 Time Based Checks T1204.004 Malicious Copy and Paste T1083 File and Directory Discovery T1134.001 Token Impersonation/Theft T1570 Lateral Tool Transfer T1016 System Network Configuration Discovery T1016.001 Internet Connection Discovery T1055.001 Dynamic-link Library Injection T1559 Inter-Process Communication T1573.001 Symmetric Cryptography T1087 Account Discovery T1005 Data from Local System T1053 Scheduled Task/Job T1027.002 Software Packing T1204.003 Malicious Image T1102 Web Service T1567.002 Exfiltration to Cloud Storage T1102.002 Bidirectional Communication T1583.001 Domains T1571 Non-Standard Port

Reporting

Research mentioning Havoc

Aug 20
Splunk Research

Detection: Windows Phantom DLL Created on Disk | Splunk Security Content

NightmareEclipse released ShieldBreak, a proof-of-concept local privilege-escalation exploit claimed to bypass Microsoft’s fix for CVE-2026-50656 (RoguePlanet). The exploit allegedly abuses improper link resolution during Windows Defender remediation, combining Cloud Files placeholders, Object Manager symbolic-link swaps, CLFS path handling, an EICAR-triggered scan, and NTFS alternate data streams to redirect a Defender process running as SYSTEM and plant C:\Windows\System32\phoneinfo.dll. A fabricated Windows Error Reporting report and the QueueReporting scheduled task then cause wermgr.exe to load the malicious DLL; the included Warden.dll payload reportedly duplicates a SYSTEM token and opens a SYSTEM shell in the unprivileged user’s session. Splunk published attack data and multiple disabled-by-default analytics for the ShieldBreak chain, covering Defender activity on \globalroot\ object-manager paths (Defender Operational events 1116/1117), MpClient.dll loaded by non-Defender processes, ADS creation through loopback administrative SMB shares (Security event 5145), manually created .wer files in the Windows Error Reporting ReportQueue, creation of phantom DLLs such as phoneinfo.dll in system paths, and WerMgr.exe spawning SYSTEM-integrity children. Organizations should collect the required Sysmon, Security, and Defender Operational telemetry; enable file-share object-access auditing; investigate these signals promptly; and validate the creating process, signer, file hash, and operational need before suppressing alerts.

Aug 19
Splunk Research

Detection: Windows Defender MpClient.dll Loaded by Non-Defender Process | Splunk Security Content

Aug 19
Splunk Research

Detection: Windows Alternate Data Stream Created Over Local Share | Splunk Security Content

Aug 18
Splunk Research

Detection: Windows Defender Threat Detected on Kernel Object Path | Splunk Security Content

Aug 18
Splunk Research

Detection: Windows Error Report Created in ReportQueue Manually | Splunk Security Content

Aug 18
Splunk Research

Detection: Windows Wermgr Spawning System Integrity Process | Splunk Security Content

Aug 17
Splunk Research

Shieldbreak | Splunk Security Content

Aug 14
Gurucul Threat Research

PATCHCORD: New Malware Cluster Targets Afghan Telecom and South Asian Critical Infrastructure | Community Portal | Gurucul

Researchers reported an active cyber espionage campaign linked with moderate confidence to APT36 (Transparent Tribe) that is targeting telecom, government, defense, energy, and other critical infrastructure organizations across South Asia, including lures tied to Afghan Telecom, government updates, and software installers. The operation uses a malware cluster that includes HACKERAI C2 Agent, PATCHCORD, and SHEETCORD, showing an evolution from earlier custom C/C++ tooling to newer Go-based implants. The malware uses legitimate cloud services as covert command-and-control channels, with HACKERAI abusing GitHub Gists and SHEETCORD using Google Sheets for command traffic and possible data exfiltration. Researchers said HACKERAI can gather system information, execute remote commands, and maintain persistence by modifying browser shortcuts while still opening the legitimate browser to avoid suspicion; published defensive leads include suspicious GitHub activity, altered browser shortcuts, malicious ZIP or installer files, and a set of reported IOCs including domains, an IP address, and multiple SHA-256 hashes.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.