Adaptix C2 is a relatively new command-and-control/post-exploitation framework referenced as being adopted quickly by malicious actors. In the provided reporting, it is described as command-and-control infrastructure used in Operation DUPEHIKE, a malware campaign dated December 5, 2025 that targeted Russian human resources personnel using a bonus-themed lure. That operation reportedly delivered the DUPERUNNER malware and involved process injection alongside use of Adaptix C2. Beyond its role as C2 infrastructure and its association with that campaign, the provided content does not supply further high-confidence technical details on Adaptix C2’s internal capabilities, supported platforms, protocols, or specific indicators of compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
“CVE-2020-1472, also known as ZeroLogon, allows for compromising a vulnerable operating system and executing commands as a privileged user.” | “CVE-2021-34527, also known as PrintNightmare… enabling remote access to a vulnerable OS and high-privilege command execution.”
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Relatively new post-exploitation/C2 framework referenced as being adopted by malicious actors.
Referenced as a command-and-control component delivered alongside DUPERUNNER via process injection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.