RalfHacker is a Russia-linked threat actor persona assessed to be involved in the development and promotion of AdaptixC2, an open-source post-exploitation framework. The persona has been identified as managing a Russian-language sales Telegram channel for AdaptixC2, indicating a role in operational support and distribution within the Russian-speaking cybercrime ecosystem. AdaptixC2 has been associated with malicious intrusions and has gained traction among threat actors because of its modular architecture, cross-platform agent support, encrypted command-and-control options, and features that facilitate stealth and persistence. Reported capabilities associated with AdaptixC2-enabled activity include command execution, credential harvesting, in-memory execution, DLL hijacking, and registry-based persistence, as well as flexible command-and-control over multiple protocols. The framework has also been observed in intrusion activity linked to Akira and Fog ransomware operations. Based on available reporting, RalfHacker is best characterized as a developer and promoter tied to a post-exploitation framework used by criminal actors rather than as a fully profiled intrusion cluster with independently documented victimology. The available evidence supports a Russia nexus and involvement in tooling that enables post-compromise operations, persistence, defense evasion, and credential theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.