Apollo is an agent for the open-source Mythic command-and-control framework, most commonly recognized as a .NET implant focused on Windows post-exploitation. It is used to manage compromised hosts after initial access and has been observed both as a stock Mythic component and in customized forms used by threat actors. Public reporting also describes Apollo in broader Mythic contexts as a post-exploitation agent used to control compromised systems, but the strongest support ties Apollo specifically to the Windows .NET implementation.
Apollo provides operators with remote command execution and post-compromise control functions. Documented behavior includes execution of PowerShell commands and the ability to create and inject into processes such as Rundll32, making it suitable for in-memory execution and defense evasion during later intrusion stages. Reporting on Mythic usage also associates Apollo-enabled operations with credential dumping and lateral movement through auxiliary tooling integrated into the Mythic ecosystem.
Apollo has been observed in real-world intrusions by multiple actors. Customized Apollo implants were previously used by Stealth Falcon, an espionage-focused threat actor targeting government and defense entities in the Middle East and Africa, before the group transitioned to the more advanced Horus Agent. Apollo has also been identified in campaigns linked with interconnected pro-Ukrainian hacktivist clusters including 4BID and associated groups, where it appeared alongside other post-exploitation frameworks, remote-management tools, and ransomware in compromises of organizations across Russia, Belarus, Kazakhstan, the UAE, Syria, and Egypt.
Available reporting does not establish a unique initial delivery mechanism intrinsic to Apollo itself; instead, it is typically deployed after access has already been obtained through other means such as exploitation or phishing-delivered intrusion chains. Apollo is therefore best characterized as a Windows post-exploitation implant within Mythic rather than a standalone initial-access malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Microsoft patched a zero-day vulnerability in its web application framework exploited by an Emirati threat group as part of an espionage campaign in the Middle East and Africa. The flaw, tracked as CVE-2025-33053, is a remote code execution vulnerability in Web Distributed Authoring and Versioning, or WebDAV.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Название «Mythic» в имени кластера отражает использование Mythic C2 - открытого фреймворка для post-exploitation с множеством агентов (Apollo, Medusa, Athena).
Named after the Egyptian falcon-headed sky god, Horus Agent represents an evolution from the group’s previously used customized Apollo implant.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Агент фреймворка Mythic C2 для post-exploitation, упомянутый как часть инструментария, связанного с Mythic Likho.
Cross-platform Mythic agent that maintains C2 connectivity and supports command execution, file transfer, arbitrary code execution, and plugin-based extension. The observed .NET agent supported HTTP, TCP, WebSocket, SMB, named pipes, and web-shell transports.
Cross-platform post-exploitation agent used with Mythic that maintains persistent C2 connectivity, executes commands, transfers files, runs arbitrary code, and supports multiple transport profiles and plugins.
Mythic C2 agent (Apollo), including a .NET variant; referenced in the context of YARA-based detection via embedded strings/classes/commands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.