Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Binary-level metadata confirms the stock agent: the compiled beacons carry a module literally named gopher, with a BOF loader and screenshot/memory-download symbols.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
AdaptixC2 is an open-source post-exploitation framework... The framework ships two agent families... listeners as loadable plugins (“extenders”) covering HTTP/S, DNS/DoH, SMB named pipes, and raw TCP transports. | BeaconHTTP : HTTP/S callback with configurable URIs, headers, and User-Agent rotation... BeaconDNS : DNS-based callback channel... BeaconTCP : Bind-style TCP channel for internal pivots
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stock AdaptixC2 demo beacon/implant deployed on Windows and Linux systems. It supports C2 communications and capabilities including BOF loading, screenshots, and memory download.
Cross-platform Go implant used by AdaptixC2. It supports asynchronous BOF execution, compiles to a statically linked binary, and communicates with operator infrastructure for command execution and persistence on compromised systems.
Gopher is a proof-of-concept ransomware for OS X, designed to demonstrate the feasibility of crypto ransomware on Mac systems. It encrypts .docx files in the user's home directory using libsodium.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.