Skip to content

PoshC2

PoshC2 is an open-source command-and-control framework and PowerShell-based implant used for post-exploitation on Windows systems.

Profile source: Mallory opens in a new tab

PoshC2

Family profile

PoshC2 is an open-source command-and-control framework and PowerShell-based implant used for post-exploitation on Windows systems. It is commonly treated as offensive security tooling, but it has also been used in real intrusions by threat actors including APT33/Elfin. The framework supports command-and-control over HTTP and HTTPS and includes proxy-aware communications options to operate in restricted enterprise environments.

PoshC2 provides a broad set of post-compromise capabilities. Documented functionality includes local and domain account enumeration, service and service-permission enumeration, port scanning, password discovery in local and remote files, decryption of credentials stored by Remote Desktop Connection Manager, process injection through modules such as Invoke-PSInject, and task execution via WMI. It also includes modules for privilege escalation to NT AUTHORITY\\SYSTEM through PowerSploit-derived Get-System functionality and can establish persistence through WMI events. Additional collection-oriented modules include recursive searching of files and directories for payment-card data and packet-capture capability on compromised hosts.

Operationally, PoshC2 is associated with Windows-centric intrusions and is frequently grouped with other dual-use C2 frameworks such as Cobalt Strike, Empire, Covenant, Mythic, and Sliver. In observed malicious use, it has been delivered as a PowerShell backdoor and used alongside scheduled-task persistence, credential dumping, defense-evasion measures, and follow-on deployment of additional implants and exfiltration tooling. Its combination of modular post-exploitation features, native Windows tradecraft, and flexible C2 transport has made it useful both for red-team operations and for adversaries conducting espionage or broader enterprise compromise.

Capabilities

  • Brute Force
  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Privilege Escalation
  • Process Injection
  • Reconnaissance
  • Scanning

Reported operators

Threat actors

1 named in public reporting
APT33

This script in turn downloaded and executed a PowerShell backdoor known as POSHC2, a proxy-aware C&C framework, from the C&C server.

Exploited software

Vulnerabilities linked to PoshC2

3 CVEs

MITRE ATT&CK

PoshC2 in ATT&CK

45 distinct techniques

Reporting

Research mentioning PoshC2

Aug 3
Securelist

Incident response statistics and cases at educational institutions in Brazil | Securelist

Brazilian educational institutions faced a sustained wave of cyber incidents in incident-response cases reviewed from January 2025 through June 2026, with attackers most often gaining access through valid accounts, exploitation of public-facing applications, insider activity, and weak patch management. High-severity cases were dominated by ransomware, particularly DragonForce and LockBit 3, and private institutions were more frequently affected than public ones. Investigators also found that outdated and unpatched systems, including Windows 10 deployments kept past end of support and unpatched Windows Server 2016 hosts, materially increased exposure. Representative intrusions showed attackers relying on common but effective techniques rather than novel tradecraft. One LockBit case involved a custom deployment built from the leaked builder and spread with PsExec, aligning with the well-documented abuse of Windows service execution for lateral movement and payload launch. Another DragonForce intrusion used AnyDesk and log wiping to maintain access and hinder response, while a separate insider case involved a Python keylogger installed on a shared machine to capture credentials. The findings underscore the need for MFA, least privilege, removal of shared accounts, tighter control of remote-access tools, stronger backups, centralized logging, longer EDR retention, and faster patching.

Mar 9
Mitre Attack Website

Compromise Accounts, Technique T1586 - Enterprise | MITRE ATT&CKĀ®

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.