Mythic Agent
Mythic Agent is a post-exploitation implant built on the Mythic C2 framework that provides remote-access capabilities including command execution, reconnaissance, file exfiltration, lateral movement, C2 communication, payload delivery, and additional plugin loading. The content links it primarily to RomCom activity in 2025, including campaigns exploiting the WinRAR zero-day CVE-2025-8088 and a separate campaign in which SocGholish fake-update infections delivered a targeted Mythic Agent loader to U.S. companies supporting Ukraine, including a U.S. civil engineering firm. RomCom is described as Russia-aligned and also tracked as Storm-0978, Tropical Scorpius, and UNC2596; Arctic Wolf assessed related targeting patterns as aligning with GRU Unit 29155. In the WinRAR exploitation chains, malicious RAR archives disguised as CVs or job applications used alternate data streams to drop LNK and DLL/EXE payloads, including a Mythic Agent chain in which Updater.lnk established persistence via COM hijacking by setting HKCU\SOFTWARE\Classes\CLSID{1299CF18-C4F5-4B6A-BB0F-2299F0398E27}\InprocServer32 to %TEMP%\msedge.dll. The msedge.dll payload decrypted embedded AES-encrypted shellcode and launched the Mythic agent; one observed C2 endpoint was https://srlaptop[.]com/s/0.7.8/clarity.js. Arctic Wolf also described a SocGholish-delivered RomCom loader disguised as msedge.dll that executed only if the victim Active Directory domain matched a hardcoded value, then decrypted shellcode identified as a Mythic dynamichttp agent; a reported C2 URL in that activity was https://imprimerie-agp[.]com/s/0.7.8/clarity.js. The malware was observed alongside other RomCom payloads such as SnipBot and RustyClaw. Separately, the content notes Mythic Agent was found on a compromised Microsoft Exchange server in a 2025 investigation involving likely Erudite Mogwai/Space Pirates activity, where it was listed among multiple co-resident malware families; in that reporting, Mythic Agent is attributed to GOFFEE.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Vulnerabilities exploited
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
...источником их заражения оказался почтовый сервер Exchange, который оказался скомпрометированным еще летом 2024 года с помощью эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
The vulnerability, tracked as CVE-2025-8088, affects all Windows versions of WinRAR up to 7.12 ... a path traversal bug that leverages Window’s alternate data streams (ADS) feature to circumvent normal file extraction safeguards.
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Mythic Agent is a sophisticated implant built on the Mythic C2 framework, designed to grant attackers powerful remote-access capabilities, including command execution, reconnaissance, file exfiltration, lateral movement, and additional plugin loading.
...были обнаружены различные файлы вредоносного ПО: ... Mythic Agent (GOFFEE)
Techniques & procedures
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
1 technique«…источником их заражения оказался почтовый сервер Exchange, который оказался скомпрометированным еще летом 2024 года с помощью эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).»
Execution
2 techniquesThe backdoor used by the group is capable of executing commands and downloading additional modules to the victim’s machine.
ESET researchers have discovered a previously unknown zero-day vulnerability in WinRAR being exploited in the wild by Russia-aligned group RomCom... The vulnerability, CVE-2025-8088, is a path traversal vulnerability... Disguised as an application document, the weaponized archives exploited a path traversal flow to compromise its targets.
Privilege Escalation
1 techniqueStealth
3 techniquesPowerTaskel загружает бинарный агент с командного сервера, внедряет его в память своего процесса и запускает в отдельном потоке
The vulnerability, CVE-2025-8088, is a path traversal vulnerability, which is made possible via the use of alternate data streams.
Третий скрипт отвечает за выделение памяти, загрузку шелл-кода из HTA-файла ... и передачу управления загруженному шелл-коду
Command and Control
1 techniqueThe backdoor used by the group is capable of executing commands and downloading additional modules to the victim’s machine.
IOCs tracked for this family
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Recent activity
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Post-exploitation agent/payload delivered in a RomCom intrusion chain (via SocGholish) to provide remote control capabilities.
Referenced as an agent/implant from the Mythic post-exploitation framework found on the compromised system; associated in the text with GOFFEE. No further details provided.
Mythic Agent is a remote access trojan (RAT) delivered via SocGholish, used for persistent access and control over victim systems.
Mythic Agent is a remote access trojan (RAT) delivered via SocGholish in targeted attacks.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.