Havoc is an open-source command-and-control and post-exploitation framework created by C5pider and first released in October 2022. Its proprietary implant, called Demon, can be generated as an executable, DLL, or shellcode payload and communicates with a Havoc team server over HTTP(S) or SMB. The framework provides multi-operator command-and-control, configurable beacon timing, shell command execution, file transfer, and Beacon Object File execution. Demon traffic uses AES-256-CTR encryption and commonly incorporates configurable sleep-obfuscation techniques.
Havoc has been used in malicious Windows intrusions by multiple threat actors, including Bitter, Transparent Tribe, and Iranian activity assessed as Lemon Sandstorm-related. Observed operations have delivered Havoc through spearphishing lures and have loaded its payloads through PowerShell, custom loaders, DLL side-loading, scheduled tasks, and process-injection chains. Threat actors have also paired Havoc with tools intended to impair endpoint defenses. Havoc has appeared in espionage, critical-infrastructure targeting, and ransomware-affiliate intrusions, as well as legitimate red-team activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Around the same time, Check Point also reported that another high-severity security flaw in the TrueConf client (CVE-2026-3502) was exploited in the wild as a zero-day as part of a campaign targeting government entities in Southeast Asia to deploy the Havoc C2 framework. | Check Point also reported that another high-severity security flaw in the TrueConf client (CVE-2026-3502) was exploited in the wild as a zero-day as part of a campaign targeting government entities in Southeast Asia to deploy the Havoc C2 framework.
Researchers at Sophos recently discovered that in mid-2025, Bronze Butler (a.k.a. Tick, RedBaldKnight, Stalker Panda, Swirl Typhoon) exploited a critical vulnerability in Lanscope when it was still a zero-day... Motex disclosed a vulnerability designated CVE-2025-61932... Motex has released a fix... CISA added CVE-2025-61932 to its Known Exploited Vulnerabilities (KEV) catalog.
Attack chains mounted by the adversary have been found to abuse CVE-2025-8088, a now-patched security flaw impacting RARLAB WinRAR that allows for arbitrary code execution when specially crafted archives are opened by targets. The exploitation of the vulnerability was observed about eight days after its public disclosure in August.
22 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Variantes observées par la CTU : Havoc — acronis.exe, hwaudkiller.exe, sophos.exe, Sophos2.exe, Sophos3.exe.
Variante Windows # Basée sur le framework Havoc avec des capacités post-exploitation personnalisées
This executes a Havoc payload. Created using domain administrator account. | The payload component was identified as a Havoc agent.
Proofpoint observed Bitter using KugelBlitz to deploy the Havoc C2 framework during hands-on activities.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
«Resource Development: приобретение ... VPS (T1583.003)»; «Short-haul redirector — облачный VPS на отдельном провайдере».
Table 11. Scheduled tasks created by the adversary throughout the reported intrusion... The heavy use of scheduled tasks to execute malware aligns with previous Lemon Sandstorm activity. | These backdoors were run using scheduled tasks.
we successfully phished some of the client staff, and lured them to execute a payload that provided us with Command & Control (C2) access.
In the context of Havoc, a shell or PowerShell command is specified by the attacker, and this opens cmd exe or powershell exe, respectively.
Table 11. Scheduled tasks created by the adversary throughout the reported intrusion... The heavy use of scheduled tasks to execute malware aligns with previous Lemon Sandstorm activity. | These backdoors were run using scheduled tasks.
config_r['inj_target32'] = extract_str(4*5, struct_b, config_r['inj_target_len32']) ... config_r['inj_target64'] = extract_str(current_offset, struct_b, config_r['inj_target_len64'])
The DemonInit function is responsible for loading modules like ntdll.dll and kernel32.dll via PEB (Process-Environment Block). It then resolves or retrieves the functions from those loaded modules...
config_r['inj_target32'] = extract_str(4*5, struct_b, config_r['inj_target_len32']) ... config_r['inj_target64'] = extract_str(current_offset, struct_b, config_r['inj_target_len64'])
The shellcode turned out to be a malicious Havoc DLL ... the loader spawns the notepad.exe process in a suspended mode ... using NTAPIs, it is written into memory.
Finally, the compressed and encoded shellcode is obtained via Base64 decoding and LZMA decompression. Now, after the shellcode is decoded, crypto algorithms like AES/RC4 are used to decrypt it.
The RaaS operators provide affiliates with a suite of custom and publicly available EDR-killing tools that abuse vulnerable drivers via the BYOVD (Bring Your Own Vulnerable Driver) technique.
the payload deployed to the targets via the phishing was crafted in a way to run the C2 agent code in both Microsoft Edge and Google Chrome browser processes on each victim's host
«URI и заголовки имитируют легитимные API-эндпоинты ... Accept, Accept-Language, X-Requested-With — как у реального AJAX-запроса».
config_r['http_method'] = extract_str(current_offset, struct_b, config_r['http_method_len']) ... config_r['host'] = extract_str(current_offset, struct_b, config_r['host_len'])
«Web Protocols (T1071.001)»; «C2-трафик маршрутизируется по совпадению URI-паттерна и кастомного заголовка».
At the time of writing, Havoc supports HTTP(s) and SMB as a communication protocol for the implants.
«Каналы управления — тактику Command and Control: External Proxy (T1090.002)»; «CDN или коммерческий reverse proxy ... принимает трафик от имплантов».
«Multi-hop Proxy (T1090.003)»; «между имплантом и тимсервером — минимум два слоя redirector'ов».
130 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
115 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Command-and-control framework observed on one host in a multi-framework cluster assessed as likely shared lab or training infrastructure.
Outil de neutralisation des EDR observé dans deux intrusions The Gentlemen, avec des exécutables ciblant notamment les processus Sophos EDR.
An EDR-killing tool observed in The Gentlemen ransomware intrusions, including binaries intended to target security products.
An EDR-killing toolset observed in The Gentlemen ransomware intrusions, used to target and disable endpoint-security processes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.