Skip to content

Mythic

Mythic is an open-source, cross-platform post-exploitation command-and-control framework developed with an agent-agnostic, modular architecture that separates the management platform from payloads.

Profile source: Mallory opens in a new tab

Mythic

Family profile

Mythic is an open-source, cross-platform post-exploitation command-and-control framework developed with an agent-agnostic, modular architecture that separates the management platform from payloads. It is widely used in adversary emulation and red teaming, but has also been repeatedly observed in real intrusions conducted by espionage and financially motivated actors. Public reporting has linked its use to groups including SideCopy, APT36/Transparent Tribe, GOFFEE, and other operators deploying Mythic-compatible implants during follow-on intrusion activity.

The framework supports multiple command-and-control transports, including HTTP, TCP, DNS, and SMB, and provides operators with flexible payload generation for Windows, Linux, and macOS. Known Mythic agents include Apollo for Windows, Poseidon for macOS, and Apfell for macOS, while private or customized Mythic-compatible agents have also been observed. Mythic is designed for post-compromise operations rather than initial exploitation, enabling operators to execute commands, conduct reconnaissance, transfer files, manage implants, and support data exfiltration. File transfer functionality includes configurable chunk sizes for uploads and downloads.

In intrusion activity, Mythic has been used after phishing- or loader-based compromise to maintain persistent access and manage victim environments. It has appeared in campaigns where weaponized documents, malicious macros, and script-based execution chains delivered in-memory payloads, as well as in financially motivated operations where loaders such as BLISTER deployed a Mythic implant. Reporting also describes Mythic agents operating in Linux container environments, including fileless execution from anonymous memory, illustrating its adaptability beyond traditional endpoints.

Because Mythic is open source, actively maintained, and easy to customize, it has become a notable alternative to frameworks such as Cobalt Strike and Sliver. Its widespread reuse by both legitimate security teams and malicious actors complicates attribution, but its role as a mature post-exploitation and command-and-control platform is well established.

Capabilities

  • Exfiltration
  • Persistence
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 24, 2026
Last activity
Aug 29, 2026
Feed role
C2
Host form
13 IP / 0 hostnames

Leading locations

  • MU2
  • SG2
  • US2
  • AT1
  • DE1
  • FI1
  • HK1
  • IN1
  • MX1
  • TR1

Leading providers

  • Mauritius Telecom Ltd2
  • Amazon.com, Inc.1
  • Antbox Networks Limited1
  • Baxet Group Inc.1
  • Eons Data Communications Limited1
  • Hetzner Online GmbH1

Infrastructure traits

  • Hosting 10

Reported operators

Threat actors

5 named in public reporting
GOFFEE

GOFFEE utilized legitimate utilities and the Mythic agent to conduct reconnaissance, access credentials, and carry out follow-up activities in container environments.

Transparent Tribe

The Pakistan-linked threat actors SideCopy and APT36 (also known as Transparent Tribe) are actively conducting sophisticated cyber espionage campaigns utilizing a diverse arsenal of attack vectors... and advanced Mythic Command and Control (C2) frameworks for persistent network access and data exfiltration operations.

RomCom

Successful exploitation attempts delivered various backdoors used by the RomCom group, specifically a SnipBot variant, RustyClaw, and the Mythic agent.

INDRIK SPIDER

"Three minutes prior to the delivery of RomCom’s shellcode loader, the operator tests the connection to Mythic C2."

ShadowSyndicate

ShadowSyndicate continues to be associated with toolkits including Cobalt Strike, Metasploit, Havoc, Mythic, Sliver, AsyncRAT, MeshAgent, and Brute Ratel.

Exploited software

Vulnerabilities linked to Mythic

2 CVEs

MITRE ATT&CK

Mythic in ATT&CK

56 distinct techniques

Techniques

56 techniques
T1059.001 PowerShell T1041 Exfiltration Over C2 Channel T1518.001 Security Software Discovery T1027.002 Software Packing T1562.001 Disable or Modify Tools T1124 System Time Discovery T1497 Virtualization/Sandbox Evasion T1105 Ingress Tool Transfer T1082 System Information Discovery T1018 Remote System Discovery T1010 Application Window Discovery T1027 Obfuscated Files or Information T1070.006 Timestomp T1055 Process Injection T1053 Scheduled Task/Job T1016 System Network Configuration Discovery T1057 Process Discovery T1071 Application Layer Protocol T1055.012 Process Hollowing T1090 Proxy T1071.001 Web Protocols T1572 Protocol Tunneling T1027.011 Fileless Storage T1574 Hijack Execution Flow T1613 Container and Resource Discovery T1059.004 Unix Shell T1547.001 Registry Run Keys / Startup Folder T1021.004 SSH T1204.002 Malicious File T1059.005 Visual Basic T1036 Masquerading T1059.007 JavaScript T1218 System Binary Proxy Execution T1547.015 Login Items T1059 Command and Scripting Interpreter T1553 Subvert Trust Controls T1553.001 Gatekeeper Bypass T1059.002 AppleScript T1030 Data Transfer Size Limits T1071.004 DNS T1119 Automated Collection T1195.001 Compromise Software Dependencies and Development Tools T1090.003 Multi-hop Proxy T1573 Encrypted Channel T1548 Abuse Elevation Control Mechanism T1570 Lateral Tool Transfer T1046 Network Service Discovery T1210 Exploitation of Remote Services T1480.001 Environmental Keying T1112 Modify Registry T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution T1564.004 NTFS File Attributes T1546.015 Component Object Model Hijacking T1573.002 Asymmetric Cryptography T1204.003 Malicious Image

Reporting

Research mentioning Mythic

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.