Havoc is an open-source command-and-control and post-exploitation framework created by C5pider and released in 2022. Its proprietary implant, known as Demon, can be generated as an executable, DLL, or shellcode payload and supports HTTP(S) and SMB communications. Havoc provides operator-managed tasking, command execution, Beacon Object File execution, file and screenshot handling, configurable sleep and jitter settings, and sleep-obfuscation techniques including Foliage, Ekko, and WaitForSingleObjectEx. Its payload configuration can include process-injection targets and options intended to bypass AMSI and ETW monitoring.
Havoc has been abused by multiple threat actors in espionage, critical-infrastructure, and ransomware-related intrusions. Observed deployments include campaigns associated with Bitter, Transparent Tribe, Lemon Sandstorm, and an activity cluster targeting Czech government and military interests. Operators have delivered Havoc through social-engineering lures, used loaders to execute Demon payloads in memory, and sideloaded malicious payloads through legitimate executables. Havoc-derived or customized functionality has also appeared in Windows backdoors that implement process injection, privilege escalation, credential theft, and BYOVD-based endpoint-security impairment. Havoc is principally associated with Windows payload deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Around the same time, Check Point also reported that another high-severity security flaw in the TrueConf client (CVE-2026-3502) was exploited in the wild as a zero-day as part of a campaign targeting government entities in Southeast Asia to deploy the Havoc C2 framework. | Check Point also reported that another high-severity security flaw in the TrueConf client (CVE-2026-3502) was exploited in the wild as a zero-day as part of a campaign targeting government entities in Southeast Asia to deploy the Havoc C2 framework.
Researchers at Sophos recently discovered that in mid-2025, Bronze Butler (a.k.a. Tick, RedBaldKnight, Stalker Panda, Swirl Typhoon) exploited a critical vulnerability in Lanscope when it was still a zero-day... Motex disclosed a vulnerability designated CVE-2025-61932... Motex has released a fix... CISA added CVE-2025-61932 to its Known Exploited Vulnerabilities (KEV) catalog.
Attack chains mounted by the adversary have been found to abuse CVE-2025-8088, a now-patched security flaw impacting RARLAB WinRAR that allows for arbitrary code execution when specially crafted archives are opened by targets. The exploitation of the vulnerability was observed about eight days after its public disclosure in August.
22 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CTU researchers observed a combination of these tools across intrusions... Havoc: acronis.exe, hwaudkiller.exe, sophos.exe, Sophos2.exe, Sophos3.exe.
Variante Windows # Basée sur le framework Havoc avec des capacités post-exploitation personnalisées
This executes a Havoc payload. Created using domain administrator account. | The payload component was identified as a Havoc agent.
Proofpoint observed Bitter using KugelBlitz to deploy the Havoc C2 framework during hands-on activities.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
«Resource Development: приобретение ... VPS (T1583.003)»; «Short-haul redirector — облачный VPS на отдельном провайдере».
Table 11. Scheduled tasks created by the adversary throughout the reported intrusion... The heavy use of scheduled tasks to execute malware aligns with previous Lemon Sandstorm activity. | These backdoors were run using scheduled tasks.
we successfully phished some of the client staff, and lured them to execute a payload that provided us with Command & Control (C2) access.
In the context of Havoc, a shell or PowerShell command is specified by the attacker, and this opens cmd exe or powershell exe, respectively.
Table 11. Scheduled tasks created by the adversary throughout the reported intrusion... The heavy use of scheduled tasks to execute malware aligns with previous Lemon Sandstorm activity. | These backdoors were run using scheduled tasks.
config_r['inj_target32'] = extract_str(4*5, struct_b, config_r['inj_target_len32']) ... config_r['inj_target64'] = extract_str(current_offset, struct_b, config_r['inj_target_len64'])
setup.ps1 launches documents.exe (Java packer) → jar.exe; ... The stub.exe Havoc payload was unknown to VirusTotal at time of capture, indicating fresh, in-the-wild tooling.
The DemonInit function is responsible for loading modules like ntdll.dll and kernel32.dll via PEB (Process-Environment Block). It then resolves or retrieves the functions from those loaded modules...
config_r['inj_target32'] = extract_str(4*5, struct_b, config_r['inj_target_len32']) ... config_r['inj_target64'] = extract_str(current_offset, struct_b, config_r['inj_target_len64'])
The shellcode turned out to be a malicious Havoc DLL ... the loader spawns the notepad.exe process in a suspended mode ... using NTAPIs, it is written into memory.
Finally, the compressed and encoded shellcode is obtained via Base64 decoding and LZMA decompression. Now, after the shellcode is decoded, crypto algorithms like AES/RC4 are used to decrypt it.
EDR-killing tools ... abuse vulnerable drivers via the BYOVD (Bring Your Own Vulnerable Driver) technique.
the payload deployed to the targets via the phishing was crafted in a way to run the C2 agent code in both Microsoft Edge and Google Chrome browser processes on each victim's host
«URI и заголовки имитируют легитимные API-эндпоинты ... Accept, Accept-Language, X-Requested-With — как у реального AJAX-запроса».
config_r['http_method'] = extract_str(current_offset, struct_b, config_r['http_method_len']) ... config_r['host'] = extract_str(current_offset, struct_b, config_r['host_len'])
«Web Protocols (T1071.001)»; «C2-трафик маршрутизируется по совпадению URI-паттерна и кастомного заголовка».
At the time of writing, Havoc supports HTTP(s) and SMB as a communication protocol for the implants.
«Каналы управления — тактику Command and Control: External Proxy (T1090.002)»; «CDN или коммерческий reverse proxy ... принимает трафик от имплантов».
«Multi-hop Proxy (T1090.003)»; «между имплантом и тимсервером — минимум два слоя redirector'ов».
130 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
112 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An EDR-killing tool observed in The Gentlemen ransomware intrusions, including binaries intended to target security products.
Оффенсивный C2-фреймворк, который в материале указан как полезная нагрузка для загрузчика Warcode.
Adversary emulation/C2 framework forming the basis of the Windows SPECTRE variant with custom post-exploitation capabilities.
Referenced as prior research involving SharePoint and Graph API dead-drop C2, not as the subject of this report.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.