Last seven days
- First activity
- Sep 2, 2026
- Last activity
- Sep 8, 2026
- Feed role
- C2 / Distribution
- Host form
- 10 IP / 0 hostnames
Havoc is an open-source command-and-control and post-exploitation framework created by C5pider and first released in October 2022.
Profile source: Mallory opens in a new tabHavoc
Havoc is an open-source command-and-control and post-exploitation framework created by C5pider and first released in October 2022. Written across Golang, C++, and Qt components, it uses a teamserver-client architecture and deploys proprietary implants known as Demons. Havoc can generate executable, DLL, and shellcode payloads, supports HTTP(S) and SMB communications, and enables post-exploitation tasking including Beacon Object File execution. Its agents employ AES-256-CTR-protected communications and can use sleep-obfuscation techniques such as Ekko, Foliage, and WaitForSingleObjectEx to hinder behavioral detection. Havoc has been adopted in real-world intrusions by multiple threat actors, including Bitter, Transparent Tribe, and Iranian activity assessed as Lemon Sandstorm; it has also appeared in campaigns targeting government, military, and critical-infrastructure organizations. Observed deployments have used DLL side-loading and scheduled-task execution, while customized Havoc-derived implants have added process injection, privilege escalation, credential theft, and endpoint-security impairment capabilities.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
Variantes observées par la CTU : Havoc — acronis.exe, hwaudkiller.exe, sophos.exe, Sophos2.exe, Sophos3.exe.
Warcode (loader для Havoc, связующее звено со старым инструментарием APT36).
Variante Windows # Basée sur le framework Havoc avec des capacités post-exploitation personnalisées
This executes a Havoc payload. Created using domain administrator account. | The payload component was identified as a Havoc agent.
Proofpoint observed Bitter using KugelBlitz to deploy the Havoc C2 framework during hands-on activities.
in June, through the powershell loading havoc frame
The group has also used a DLL sideloading technique to launch the Havoc C2 post-exploitation framework, and establishes an SSH backdoor via AdaptixC2 or OpenSSH.
Havoc C2 for post-exploitation tasks like pivoting through compromised hosts into internal networks, privilege escalation, and maintaining stealth
The TrueChaos campaign has been found to weaponize this flaw in the update mechanism to likely deploy the open-source Havoc command-and-control (C2) framework to vulnerable endpoints.
What once ended with a $300 gift card purchase now ends with a modified Havoc C2 framework burrowed into your environment... deploying a mix of custom Havoc Demon payloads...
"...used to execute the Havoc command-and-control (C2) framework."
The attack is also characterized by the deployment of the Havoc post-exploitation framework on select systems...
OceanLotus: TahirSec has published a report on a recent OceanLotus (APT32) phishing campaign that drops Havoc payloads.
The final payload deployed as part of the attack is the open-source command-and-control (C2 or C&C) framework known as Havoc.
Lastly, some operators started experimenting with the Havoc C2 framework in March 2025, to supplement their tooling.
"...downloads and executes an additional payload, most commonly Havoc."
ShadowSyndicate continues to be associated with toolkits including Cobalt Strike, Metasploit, Havoc, Mythic, Sliver, AsyncRAT, MeshAgent, and Brute Ratel.
“The primary C2 frameworks observed were Cobalt Strike, VShell, Havoc, Sliver, and SparkRat.”
Nearly half a dozen organizations have been targeted with the Havoc command-and-control framework for subsequent data theft or ransomware compromise in a new IT support scam campaign.
This evolution includes the use of the Rust programming language, a departure from previous reliance on traditional compiled languages and frameworks like Cobalt Strike and Havoc.
"...borrowed adversary simulation frameworks such as Cobalt Strike, Havoc..." and "...components associated with the Havoc post-exploitation C2 framework... Havoc shellcode payload..."
"...borrowed adversary simulation frameworks such as Cobalt Strike, Havoc..." and "...components associated with the Havoc post-exploitation C2 framework... Havoc shellcode payload..."
Exploited software
MITRE ATT&CK
Reporting
NightmareEclipse released ShieldBreak, a proof-of-concept local privilege-escalation exploit claimed to bypass Microsoft’s fix for CVE-2026-50656 (RoguePlanet). The exploit allegedly abuses improper link resolution during Windows Defender remediation, combining Cloud Files placeholders, Object Manager symbolic-link swaps, CLFS path handling, an EICAR-triggered scan, and NTFS alternate data streams to redirect a Defender process running as SYSTEM and plant C:\Windows\System32\phoneinfo.dll. A fabricated Windows Error Reporting report and the QueueReporting scheduled task then cause wermgr.exe to load the malicious DLL; the included Warden.dll payload reportedly duplicates a SYSTEM token and opens a SYSTEM shell in the unprivileged user’s session. Splunk published attack data and multiple disabled-by-default analytics for the ShieldBreak chain, covering Defender activity on \globalroot\ object-manager paths (Defender Operational events 1116/1117), MpClient.dll loaded by non-Defender processes, ADS creation through loopback administrative SMB shares (Security event 5145), manually created .wer files in the Windows Error Reporting ReportQueue, creation of phantom DLLs such as phoneinfo.dll in system paths, and WerMgr.exe spawning SYSTEM-integrity children. Organizations should collect the required Sysmon, Security, and Defender Operational telemetry; enable file-share object-access auditing; investigate these signals promptly; and validate the creating process, signer, file hash, and operational need before suppressing alerts.
Researchers reported an active cyber espionage campaign linked with moderate confidence to APT36 (Transparent Tribe) that is targeting telecom, government, defense, energy, and other critical infrastructure organizations across South Asia, including lures tied to Afghan Telecom, government updates, and software installers. The operation uses a malware cluster that includes HACKERAI C2 Agent, PATCHCORD, and SHEETCORD, showing an evolution from earlier custom C/C++ tooling to newer Go-based implants. The malware uses legitimate cloud services as covert command-and-control channels, with HACKERAI abusing GitHub Gists and SHEETCORD using Google Sheets for command traffic and possible data exfiltration. Researchers said HACKERAI can gather system information, execute remote commands, and maintain persistence by modifying browser shortcuts while still opening the legitimate browser to avoid suspicion; published defensive leads include suspicious GitHub activity, altered browser shortcuts, malicious ZIP or installer files, and a set of reported IOCs including domains, an IP address, and multiple SHA-256 hashes.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.