Security researchers from Silent Push have identified that the open-source command and control (C2) framework AdaptixC2, originally designed for penetration testing and adversary emulation, is being actively abused by Russian-linked cybercriminals. The tool, which is freely available on GitHub and supports Linux, Windows, and macOS, has been leveraged to deliver malicious payloads in global ransomware campaigns. The investigation into AdaptixC2's misuse began during research into the CountLoader malware loader, where AdaptixC2 was observed being used to deploy additional threats, including ransomware and information stealers.
Further analysis revealed that a threat actor known as “RalfHacker” is likely the developer behind AdaptixC2 and operates a Russian-language Telegram channel to promote and sell the tool within the criminal underground. The cross-platform nature and extensibility of AdaptixC2 make it attractive for both legitimate security testing and malicious activity, enabling attackers to target a wide range of systems. Security teams have responded by developing detection signatures for both CountLoader and AdaptixC2 infrastructure to help mitigate the threat posed by this dual-use tool.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Silent Push reported that AdaptixC2 has been weaponized by multiple threat actors and identified “RalfHacker” as a likely developer or key figure behind the framework. The research further tied the tool’s development and distribution to the Russian criminal ecosystem.
Palo Alto Networks Unit 42 associated AdaptixC2-related activity with intrusions involving Akira and Fog ransomware. This connected the framework to real-world ransomware operations rather than only red-team or commodity abuse.
Researchers reported AdaptixC2 being delivered in social-engineering attacks conducted over Microsoft Teams and involving Quick Assist. The technique demonstrated active operational use of the framework for initial access and follow-on compromise.
Reporting indicated that AdaptixC2 was concealed inside a malicious npm package masquerading as an HTTPS proxy utility. This showed the framework being distributed through software supply chain-style deception.
Researchers identified a persona known as “RalfHacker” operating a Russian-language Telegram channel used to sell or promote AdaptixC2. This activity linked the framework’s ecosystem to the Russian-speaking cybercriminal underground.
AdaptixC2 emerged as a free, actively maintained open-source red-teaming and post-exploitation framework with modular, cross-platform capabilities. Its design lowered the barrier for threat actors to access enterprise-grade post-exploitation tooling.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesilentpush.com
Open sourcehackread.com
Open sourcesecurityboulevard.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.