Adaptix is a remote access and command-and-control malware/framework referenced in reporting on the China-linked Operation Dragon Weave espionage campaign. In that campaign, Adaptix was deployed as the final payload for remote control and data exfiltration against targets in the Czech Republic and Taiwan, including government and public sector, research and academia, technology and software, and financial services organizations. The infection vector described in the reporting was spearphishing emails carrying malicious ZIP attachments with government-themed lures. Two execution paths were observed: a malicious LNK launching PowerShell, or a Rust-based dropper executable; both converged on RuntimeBroker_update.exe, DLL sideloading via UnityPlayer.dll, a Rust-based loader named RUSTCLOAK, and then AZUREVEIL, described as a fully functional 64-bit Adaptix command-and-control agent. Reported Adaptix/AZUREVEIL capabilities include encrypted beaconing, command execution, file exfiltration, file operations, shell execution, process listing, port forwarding, and in-memory execution of Beacon Object Files. The malware used Microsoft Azure Blob Storage as dead-drop C2 infrastructure so that attacker commands and victim results were exchanged through encrypted blobs in a shared container, helping traffic blend with legitimate cloud activity. The reporting also notes stealth and evasion features including multi-layer encryption, in-memory execution, runtime API resolution, and sandbox evasion through machine-name checks. A reported network IOC associated with this activity is note1ggbbhggdwa1.blob.core.windows.net. Additional reporting cited infrastructure overlap or prior linkage between Adaptix-related C2 framework infrastructure and LARUS / Cloud Innovation hosting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Inside the VM, persistence and a command and control channel were established through the root crontab that launched two scripts at boot
Azureveil retrieves these commands, decrypts them, executes them, and uploads the results back as encrypted blobs.
The blog also examines how trusted services such as Microsoft Azure Blob Storage are abused for command-and-control communication, and how the Adaptix agent is used for data exfiltration and remote control. In addition, we analyze the multi-layer encryption used to protect the payload and how it helps the attacker evade detection.
Valid Accounts: Domain Accounts T1078.002 engineer, ConfigMgrNAA reuse
adversaries leveraging QEMU, an open-source machine emulator and virtualizer typically used for development and testing, to deploy virtual machines that contained and executed malicious payloads. This approach enabled them to maintain covert access and bypass host-based detection from AV and EDR solutions.
The LSASS results file contains structured output from automated credential extraction across four workstations in the ICG domain. Each dump followed the same pattern: minidump to C:\ProgramData\d.dmp , extract cached logons, enumerate local users, pull credential vaults, and harvest PowerShell history.
Network and Pivoting... Network adapter enumeration (MAC, IP, type)
Process and Shell Control Execute shell commands List running processes and named pipes
C2 Management Reconfigure C2 settings at runtime Control file transfer state Retrieve system uptime
Command Capabilities of AZUREVEIL... File System Operations List directory contents and logical drives Read, move, rename, and delete files
adversaries leveraging QEMU, an open-source machine emulator and virtualizer typically used for development and testing, to deploy virtual machines that contained and executed malicious payloads. This approach enabled them to maintain covert access and bypass host-based detection from AV and EDR solutions.
The attack uses a multi-stage infection chain and abuses Microsoft Azure Blob Storage as command-and-control infrastructure to blend malicious activity with legitimate cloud traffic.
Network and Pivoting Port forwarding and SOCKS proxy control TCP and UDP pivot connections
the beacon’s local traffic was carried over the encrypted SSH channel to remote infrastructure, enabling command-and-control communication while blending into normal outbound traffic.
"Instead of using a traditional pull-based C2 model, Azureveil follows a dead-drop approach," ... "The attacker and the infected system never communicate directly. Instead, both sides use the same Azure storage container to exchange data."
The campaign deploys the Adaptix remote access agent for data exfiltration and remote control while leveraging multi-layer encryption and stealth techniques to evade detection and maintain persistent access.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access malware used for remote control, data exfiltration, stealth, and persistent access in the Operation Dragon Weave cyberespionage campaign.
Command-and-control agent framework used as the basis for the AZUREVEIL payload in this espionage campaign.
A command-and-control framework referenced as the platform for which Azureveil acts as an agent.
Named command-and-control framework previously observed on the same LARUS / Cloud Innovation infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.