Adaptix
Adaptix is a command-and-control (C2) framework/agent referenced in reporting on multiple China-linked intrusion clusters. In Seqrite’s reporting on Operation Dragon Weave, the final payload AZUREVEIL is described as a fully functional 64-bit Adaptix C2 agent. In that campaign, victims in the Czech Republic and Taiwan were targeted via spear-phishing ZIP archives using government- and business-themed lures, including Czech Social Security Administration appointment decoys. Two execution paths were observed: a malicious LNK launching PowerShell, or a Rust-based dropper executable. Both paths converged on RuntimeBroker_update.exe, DLL sideloading via UnityPlayer.dll, and a Rust-based loader named RUSTCLOAK, which decrypted and launched AZUREVEIL in memory. RUSTCLOAK used anti-analysis checks against more than 100 known sandbox and analyst machine names. AZUREVEIL/Adaptix used Microsoft Azure Blob Storage as a dead-drop C2 channel, periodically uploading small encrypted beacons, retrieving encrypted commands from the same container, executing them, and uploading encrypted results. Reported capabilities for the AZUREVEIL Adaptix agent included command execution, file exfiltration, file operations, shell execution, process listing, port forwarding, and in-memory execution of Beacon Object Files. Seqrite assessed the broader campaign as China-linked with moderate confidence, but did not attribute it to a specific APT group. Separately, reporting cited LARUS / Cloud Innovation infrastructure as having surfaced in an Adaptix C2 framework investigation, indicating Adaptix-related infrastructure overlap with hosting previously associated with China-nexus activity.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
3 techniquesValid Accounts: Domain Accounts T1078.002 engineer, ConfigMgrNAA reuse
Initial Access └── VPN authentication as "engineer" (iSn(wXB.$DeLO1V[k+zm) └── Or "support" (DblfYjZABjbzkUR)
The attack begins with a ZIP attachment. When extracted, the archive contains multiple files that appear legitimate but are actually part of a structured infection chain designed to execute malicious payloads in the background.
Execution
4 techniquesInside the VM, persistence and a command and control channel were established through the root crontab that launched two scripts at boot
Azureveil retrieves these commands, decrypts them, executes them, and uploads the results back as encrypted blobs.
Inside the VM, persistence and a command and control channel were established through the root crontab that launched two scripts at boot... @reboot /bin/sh /sbin/syslogda.sh>/dev/null 2>&1 @reboot /bin/sh /sbin/syslogdb.sh>/dev/null 2>&1
In Path A, the infection begins when the victim clicks on the malicious LNK file 計畫申請審查結果通知單.pdf.lnk... In Path B, the victim directly runs _計畫申請審查結果通知單.exe.
Persistence
3 techniquesInside the VM, persistence and a command and control channel were established through the root crontab that launched two scripts at boot
Valid Accounts: Domain Accounts T1078.002 engineer, ConfigMgrNAA reuse
Privilege Escalation
2 techniquesStealth
3 techniquesThe blog also examines how trusted services such as Microsoft Azure Blob Storage are abused for command-and-control communication, and how the Adaptix agent is used for data exfiltration and remote control. In addition, we analyze the multi-layer encryption used to protect the payload and how it helps the attacker evade detection.
Valid Accounts: Domain Accounts T1078.002 engineer, ConfigMgrNAA reuse
adversaries leveraging QEMU, an open-source machine emulator and virtualizer typically used for development and testing, to deploy virtual machines that contained and executed malicious payloads. This approach enabled them to maintain covert access and bypass host-based detection from AV and EDR solutions.
Credential Access
2 techniquesThe LSASS results file contains structured output from automated credential extraction across four workstations in the ICG domain. Each dump followed the same pattern: minidump to C:\ProgramData\d.dmp , extract cached logons, enumerate local users, pull credential vaults, and harvest PowerShell history.
Discovery
6 techniquesNetwork and Pivoting... Network adapter enumeration (MAC, IP, type)
Process and Shell Control Execute shell commands List running processes and named pipes
C2 Management Reconfigure C2 settings at runtime Control file transfer state Retrieve system uptime
Command Capabilities of AZUREVEIL... File System Operations List directory contents and logical drives Read, move, rename, and delete files
adversaries leveraging QEMU, an open-source machine emulator and virtualizer typically used for development and testing, to deploy virtual machines that contained and executed malicious payloads. This approach enabled them to maintain covert access and bypass host-based detection from AV and EDR solutions.
Lateral Movement
2 techniquesThe script syslogdb.sh maintained an SSH connection to the C2 server over TCP 443 and forwarded local port 33443 to the C2 server through this tunnel.
Command and Control
7 techniquesAs a result, the beacon’s local traffic was carried over the encrypted SSH channel to remote infrastructure, enabling command-and-control communication while blending into normal outbound traffic.
Network and Pivoting Port forwarding and SOCKS proxy control TCP and UDP pivot connections
the beacon’s local traffic was carried over the encrypted SSH channel to remote infrastructure, enabling command-and-control communication while blending into normal outbound traffic.
"Instead of using a traditional pull-based C2 model, Azureveil follows a dead-drop approach," ... "The attacker and the infected system never communicate directly. Instead, both sides use the same Azure storage container to exchange data."
the adversaries proceeded to establish a command and control channel for persistence by deploying and launching a QEMU virtual machine from a Linux disk image named vault.db
All communication happens over HTTPS on port 443, which makes the traffic blend in with normal Azure activity.
Exfiltration
1 techniqueAzureveil retrieves these commands, decrypts them, executes them, and uploads the results back as encrypted blobs... they can execute commands and exfiltrate files from the target system...
IOCs tracked for this family
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Command-and-control agent framework used as the basis for the AZUREVEIL payload in this espionage campaign.
A command-and-control framework referenced as the platform for which Azureveil acts as an agent.
Named command-and-control framework previously observed on the same LARUS / Cloud Innovation infrastructure.
Open-source pen-testing/post-exploitation tool referenced as being used alongside Syteca by Fog ransomware operators.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.