Mythic is an open-source, cross-platform post-exploitation command-and-control framework developed with an agent-agnostic, modular architecture that separates the management platform from payloads. It is widely used in adversary emulation and red teaming, but has also been repeatedly observed in real intrusions conducted by espionage and financially motivated actors. Public reporting has linked its use to groups including SideCopy, APT36/Transparent Tribe, GOFFEE, and other operators deploying Mythic-compatible implants during follow-on intrusion activity.
The framework supports multiple command-and-control transports, including HTTP, TCP, DNS, and SMB, and provides operators with flexible payload generation for Windows, Linux, and macOS. Known Mythic agents include Apollo for Windows, Poseidon for macOS, and Apfell for macOS, while private or customized Mythic-compatible agents have also been observed. Mythic is designed for post-compromise operations rather than initial exploitation, enabling operators to execute commands, conduct reconnaissance, transfer files, manage implants, and support data exfiltration. File transfer functionality includes configurable chunk sizes for uploads and downloads.
In intrusion activity, Mythic has been used after phishing- or loader-based compromise to maintain persistent access and manage victim environments. It has appeared in campaigns where weaponized documents, malicious macros, and script-based execution chains delivered in-memory payloads, as well as in financially motivated operations where loaders such as BLISTER deployed a Mythic implant. Reporting also describes Mythic agents operating in Linux container environments, including fileless execution from anonymous memory, illustrating its adaptability beyond traditional endpoints.
Because Mythic is open source, actively maintained, and easy to customize, it has become a notable alternative to frameworks such as Cobalt Strike and Sliver. Its widespread reuse by both legitimate security teams and malicious actors complicates attribution, but its role as a mature post-exploitation and command-and-control platform is well established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ESET researchers have discovered a previously unknown zero-day vulnerability in WinRAR being exploited in the wild by Russia-aligned group RomCom... now assigned CVE-2025-8088: a path traversal vulnerability, made possible with the use of alternate data streams. | Successful exploitation attempts delivered various backdoors used by the RomCom group, specifically a SnipBot variant, RustyClaw, and the Mythic agent.
Three Attack Variants Observed GrimResource (CVE-2025-26633): XSS via apds.dll res:// protocol handler
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GOFFEE utilized legitimate utilities and the Mythic agent to conduct reconnaissance, access credentials, and carry out follow-up activities in container environments.
The Pakistan-linked threat actors SideCopy and APT36 (also known as Transparent Tribe) are actively conducting sophisticated cyber espionage campaigns utilizing a diverse arsenal of attack vectors... and advanced Mythic Command and Control (C2) frameworks for persistent network access and data exfiltration operations.
Successful exploitation attempts delivered various backdoors used by the RomCom group, specifically a SnipBot variant, RustyClaw, and the Mythic agent.
"Three minutes prior to the delivery of RomCom’s shellcode loader, the operator tests the connection to Mythic C2."
ShadowSyndicate continues to be associated with toolkits including Cobalt Strike, Metasploit, Havoc, Mythic, Sliver, AsyncRAT, MeshAgent, and Brute Ratel.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Matrix: This MITRE ATT&CK Matrix is a summary of the combined capabilities of every Mythic agent (Apollo, Athena, Tetanus, etc.): Technique Technique ID Observable Scheduled Task/Job T1053
This script generates an Office macro which uses osascript to download and execute the Mythic JXA .js payload.
PowerTaskel v2 — «модифицированный PowerShell-агент Mythic», предназначенный для «выполнения полученных от него PowerShell-команд».
В качестве точки запуска предположительно был задействован штатный сценарий сервиса RabbitMQ ... /opt/bitnami/scripts/rabbitmq/setup.sh
This script generates an Office macro which uses osascript to download and execute the Mythic JXA .js payload.
MITRE ATT&CK Matrix: This MITRE ATT&CK Matrix is a summary of the combined capabilities of every Mythic agent (Apollo, Athena, Tetanus, etc.): Technique Technique ID Observable Scheduled Task/Job T1053
MITRE ATT&CK Matrix: This MITRE ATT&CK Matrix is a summary of the combined capabilities of every Mythic agent (Apollo, Athena, Tetanus, etc.): Technique Technique ID Observable Scheduled Task/Job T1053
By the end of July, we observed campaigns involving a new BLISTER loader that targeted victim organizations to deploy the MYTHIC implant. MYTHIC running inside injected WerFault process
Пейлоад размещался в анонимной области памяти через memfd_create и выполнялся без сохранения исполняемого файла на диск.
Remove the first line of the Mythic JXA .js launcher... Some static A/V signatures have been known to check for this static string.
By the end of July, we observed campaigns involving a new BLISTER loader that targeted victim organizations to deploy the MYTHIC implant. MYTHIC running inside injected WerFault process
Developers of malware control servers often leave unique and identifying strings in web page data. Most commonly these can be found in the HTML Titles and HTTP Bodies.
Apollo can route SOCKS traffic regardless of what other commands are compiled in. To start the socks server, issue socks -Port [port] . This starts a SOCKS server on the Mythic server which is proxychains4 compatible.
136 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
58 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Agent used for reconnaissance, credential access, and follow-up activity in container environments.
Modular C2 framework discussed as a comparable tool to Sliver. It separates the control panel from agents and can build custom agents with unique network profiles.
Mythic agent was used by GOFFEE inside a Linux container as an in-memory payload, likely launched via a modified RabbitMQ script and executed filelessly through memfd_create for post-compromise operations.
The article highlights GOFFEE's use of a Mythic agent/implant, including execution inside a Linux container via a RabbitMQ service script and in-memory execution using memfd_create. It is presented as part of the group's operational tooling for command-and-control and post-compromise activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.