Last seven days
- First activity
- Aug 24, 2026
- Last activity
- Aug 29, 2026
- Feed role
- C2
- Host form
- 13 IP / 0 hostnames
Mythic is an open-source, cross-platform post-exploitation command-and-control framework developed with an agent-agnostic, modular architecture that separates the management platform from payloads.
Profile source: Mallory opens in a new tabMythic
Mythic is an open-source, cross-platform post-exploitation command-and-control framework developed with an agent-agnostic, modular architecture that separates the management platform from payloads. It is widely used in adversary emulation and red teaming, but has also been repeatedly observed in real intrusions conducted by espionage and financially motivated actors. Public reporting has linked its use to groups including SideCopy, APT36/Transparent Tribe, GOFFEE, and other operators deploying Mythic-compatible implants during follow-on intrusion activity.
The framework supports multiple command-and-control transports, including HTTP, TCP, DNS, and SMB, and provides operators with flexible payload generation for Windows, Linux, and macOS. Known Mythic agents include Apollo for Windows, Poseidon for macOS, and Apfell for macOS, while private or customized Mythic-compatible agents have also been observed. Mythic is designed for post-compromise operations rather than initial exploitation, enabling operators to execute commands, conduct reconnaissance, transfer files, manage implants, and support data exfiltration. File transfer functionality includes configurable chunk sizes for uploads and downloads.
In intrusion activity, Mythic has been used after phishing- or loader-based compromise to maintain persistent access and manage victim environments. It has appeared in campaigns where weaponized documents, malicious macros, and script-based execution chains delivered in-memory payloads, as well as in financially motivated operations where loaders such as BLISTER deployed a Mythic implant. Reporting also describes Mythic agents operating in Linux container environments, including fileless execution from anonymous memory, illustrating its adaptability beyond traditional endpoints.
Because Mythic is open source, actively maintained, and easy to customize, it has become a notable alternative to frameworks such as Cobalt Strike and Sliver. Its widespread reuse by both legitimate security teams and malicious actors complicates attribution, but its role as a mature post-exploitation and command-and-control platform is well established.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
GOFFEE utilized legitimate utilities and the Mythic agent to conduct reconnaissance, access credentials, and carry out follow-up activities in container environments.
The Pakistan-linked threat actors SideCopy and APT36 (also known as Transparent Tribe) are actively conducting sophisticated cyber espionage campaigns utilizing a diverse arsenal of attack vectors... and advanced Mythic Command and Control (C2) frameworks for persistent network access and data exfiltration operations.
Successful exploitation attempts delivered various backdoors used by the RomCom group, specifically a SnipBot variant, RustyClaw, and the Mythic agent.
"Three minutes prior to the delivery of RomCom’s shellcode loader, the operator tests the connection to Mythic C2."
ShadowSyndicate continues to be associated with toolkits including Cobalt Strike, Metasploit, Havoc, Mythic, Sliver, AsyncRAT, MeshAgent, and Brute Ratel.
Exploited software
MITRE ATT&CK
Reporting
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.