Adaptix C2 is a command-and-control framework used to manage post-compromise implants. It has been observed exposed alongside other C2 frameworks in multi-framework deployments and associated with malicious activity. A Linux ELF implant known as JITTERLY uses a protocol, configuration structure, registration process, and command format closely aligned with Adaptix C2. In Operation DUPEHIKE, Adaptix C2 infrastructure was used in an intrusion campaign targeting Russian human-resources personnel, in which a bonus-themed lure delivered DUPERUNNER and activity involved process injection. Adaptix C2 has also been associated with infrastructure attributed to the PRC-linked Red Heron activity through JITTERLY-compatible communications.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
JITTERLY's protocol, configuration fields, registration process, and command structure closely match the Linux agent used by the Adaptix C2 framework.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
“CVE-2020-1472, also known as ZeroLogon, allows for compromising a vulnerable operating system and executing commands as a privileged user.” | “CVE-2021-34527, also known as PrintNightmare… enabling remote access to a vulnerable OS and high-privilege command execution.”
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Command-and-control framework observed alongside Mythic on some hosts, including the assessed multi-framework lab/training cluster.
An open-source post-exploitation command-and-control framework whose Linux Gopher-agent protocol and command mappings are closely compatible with JITTERLY. The content describes Red Heron as relying on it for post-exploitation operations.
Relatively new post-exploitation/C2 framework referenced as being adopted by malicious actors.
Referenced as a command-and-control component delivered alongside DUPERUNNER via process injection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.