Merlin is an open-source post-exploitation command-and-control agent written in Go and commonly used as a backdoor within intrusion operations. It is compatible with the Mythic framework and supports communications over multiple HTTP-based transports, including HTTP/1.1, HTTP/2, and HTTP/3 over QUIC. Merlin has been observed in espionage-focused campaigns as a modular implant used after initial compromise to establish command-and-control, execute operator tasking, and collect host information from infected systems.
Merlin has been deployed by multiple threat clusters and is not exclusive to a single actor. It has been associated with activity attributed to Chinese state-aligned operations, including intrusions against a Southeast Asian government organization where operators used DLL sideloading through a legitimate VMware binary to load a Merlin agent. It has also been used in campaigns targeting Russian organizations, including activity tracked as Mythic Likho, where spearphishing lures led to execution of a Merlin payload disguised as a benign file and launched indirectly through a headless console utility while a decoy document was displayed to the victim. Reporting also links Merlin to prior Tropic Trooper tradecraft as a payload fetched by a loader in targeted campaigns against East Asian victims.
Observed Merlin-enabled infection chains rely on social engineering and post-compromise execution techniques rather than self-propagation. In documented cases, delivery has included spearphishing archives and shortcut-based execution chains that invoke PowerShell and living-off-the-land binaries to start the agent while masking activity with lure documents. In other operations, Merlin has been introduced through DLL sideloading using trusted executables. Once running, Merlin has been observed transmitting basic victim profiling data such as host, user, operating system, architecture, and process information to its controller over encrypted channels.
Merlin is best characterized as a publicly available backdoor or RAT used for post-exploitation, persistence support, reconnaissance, and follow-on payload delivery within broader intrusion sets. Its use by several espionage actors illustrates the continuing operational value of open-source C2 tooling in targeted attacks against government, telecom, defense, industrial, and other high-value sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Mythic Likho (Arcane Werewolf) ... Merlin agent (Go), совместимый с фреймворком Mythic
We observed the first persistence mechanism used in Cluster Alpha in March, when the attacker deployed Merlin, an open-source C2 tool written in Golang.
...has been used in the past to fetch next-stage payloads like Cobalt Strike Beacon or Merlin agent for the Mythic framework.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Cross-platform post-exploitation HTTP Command & Control agent written in golang ... This implementation uses Mythic's Default HTTP Command and Control profile
This implementation uses Mythic's Default HTTP Command and Control profile
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Go-based remote access agent compatible with the Mythic framework.
A post-exploitation agent for the Mythic framework referenced as a payload previously fetched in Tropic Trooper activity.
An open-source Golang command-and-control agent deployed via vmnat.exe DLL sideloading to establish persistence and communicate with attacker infrastructure.
Открытый исходный постэксплуатационный агент/бэкдор на Go для Windows, Linux и macOS. В данном случае используется для скрытого запуска, связи с C2 по HTTP(S), шифрования трафика AES, сбора системной информации и дальнейшей загрузки других полезных нагрузок, включая Loki 2.0.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.