Apollo is an open-source .NET post-exploitation agent for the Mythic command-and-control framework, primarily designed for Windows systems. It supports remote command execution, including PowerShell, and can create and inject into Rundll32 processes. Apollo can be used with Mimikatz functionality for credential dumping and lateral movement. Customized Apollo agents were used by Stealth Falcon between 2022 and 2023; the group later replaced them with the more advanced Horus Agent implant. Apollo has also been observed among post-exploitation tooling deployed in intrusions attributed with medium confidence to interconnected pro-Ukrainian hacktivist groups including 4BID, Hakerskii Kit, C.A.S., and Goffee. Those operations targeted organizations in Russia, Belarus, Kazakhstan, the UAE, Syria, and Egypt, including government, healthcare, and aviation entities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Microsoft patched a zero-day vulnerability in its web application framework exploited by an Emirati threat group as part of an espionage campaign in the Middle East and Africa. The flaw, tracked as CVE-2025-33053, is a remote code execution vulnerability in Web Distributed Authoring and Versioning, or WebDAV.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Название «Mythic» в имени кластера отражает использование Mythic C2 - открытого фреймворка для post-exploitation с множеством агентов (Apollo, Medusa, Athena).
Named after the Egyptian falcon-headed sky god, Horus Agent represents an evolution from the group’s previously used customized Apollo implant.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Matrix: This MITRE ATT&CK Matrix is a summary of the combined capabilities of every Mythic agent (Apollo, Athena, Tetanus, etc.): Technique Technique ID Observable Scheduled Task/Job T1053
MITRE ATT&CK Matrix: This MITRE ATT&CK Matrix is a summary of the combined capabilities of every Mythic agent (Apollo, Athena, Tetanus, etc.): Technique Technique ID Observable Scheduled Task/Job T1053
reg_query ... Query all subkeys of the specified registry path ... reg_write_value ... Write specified values to the registry keys.
MITRE ATT&CK Matrix: This MITRE ATT&CK Matrix is a summary of the combined capabilities of every Mythic agent (Apollo, Athena, Tetanus, etc.): Technique Technique ID Observable Scheduled Task/Job T1053
“On Windows targets, watch for process injection and LSASS access from non-system processes. Apollo, Mythic’s primary Windows agent, uses standard injection techniques.”
printspoofer printspoofer -Command [command] Execute a command in SYSTEM integrity so long as you have SeImpersonate privileges. | make_token make_token Impersonate a user using plaintext credentials. ... rev2self Revert the access token to the original access token. ... steal_token steal_token [pid] Attempts to steal the process's primary token specified by [pid] and apply it to our own session.
“Credential access and post-exploitation through agent-side modules for ... token impersonation.”
“On Windows targets, watch for process injection and LSASS access from non-system processes. Apollo, Mythic’s primary Windows agent, uses standard injection techniques.”
printspoofer printspoofer -Command [command] Execute a command in SYSTEM integrity so long as you have SeImpersonate privileges. | make_token make_token Impersonate a user using plaintext credentials. ... rev2self Revert the access token to the original access token. ... steal_token steal_token [pid] Attempts to steal the process's primary token specified by [pid] and apply it to our own session.
“Credential access and post-exploitation through agent-side modules for ... token impersonation.”
dcsync dcsync -Domain contoso.local [-User username -DC dc.ip] DCSync one or more user credentials ... mimikatz mimikatz -Command [args] Execute Mimikatz with the specified arguments.
net_localgroup_member net_localgroup_member -Group [groupname] [-Computer [computername]] Retrieve membership information from a specified group on a given computer. net_localgroup net_localgroup [computer] Retrieve local groups known by a computer.
System Information Discovery T1082 Read machine GUID, software policy, volume information
C2 - Web Protocols (T1071.001) ... Управление имплантами и вывод данных - через HTTPS.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mythic’s primary Windows agent; the content identifies its use of process-injection techniques and notes Windows-focused credential-access functionality, including LSASS interaction, available through Mythic agent-side modules.
Windows agent/implant for the Mythic framework, mentioned as an example of a customizable payload communicating with a C2 server.
Агент фреймворка Mythic C2 для post-exploitation, упомянутый как часть инструментария, связанного с Mythic Likho.
Cross-platform Mythic agent that maintains C2 connectivity and supports command execution, file transfer, arbitrary code execution, and plugin-based extension. The observed .NET agent supported HTTP, TCP, WebSocket, SMB, named pipes, and web-shell transports.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.