Threat actors have begun using the open-source Havoc post-exploitation framework in real-world attacks, positioning it as an alternative to tools such as Cobalt Strike, Sliver, and Brute Ratel. Researchers observed a targeted intrusion against an unnamed government organization in which attackers delivered a ZIP archive containing a decoy document and a malicious .scr file that installed the Havoc Demon implant. Once deployed, the malware enabled remote command execution, collection of command output, encryption of results, and exfiltration to attacker-controlled command-and-control infrastructure.
Analysis cited in multiple reports said Havoc includes evasion features such as indirect syscalls and sleep obfuscation, helping it bypass fully updated Windows 11 Defender protections. The framework was also linked to a malicious npm package, aabquerys, which triggered a three-stage infection chain to fetch the Demon payload before the package was removed. The activity reflects a broader trend of offensive security frameworks escaping legitimate red-team use and being repurposed by attackers for stealthy post-compromise operations.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Security reporting from Zscaler and others highlighted that attackers had begun using the open-source Havoc command-and-control framework as an alternative to tools like Cobalt Strike, Sliver, and Brute Ratel. The reports also noted Havoc's evasion features, including indirect syscalls and sleep obfuscation, which helped it bypass modern Windows defenses.
Threat actors also used a malicious npm package named aabquerys in a three-stage infection chain to retrieve the Havoc Demon implant. The package was later removed after its malicious behavior was identified.
In early January 2023, threat actors targeted an unnamed government organization with a ZIP archive containing a decoy document and a malicious screen-saver file that deployed the Havoc Demon implant. The campaign showed real-world adoption of the open-source Havoc post-exploitation framework in targeted attacks.
Researchers published fuller technical disclosure on Havex trojans, expanding public understanding of the malware's behavior and capabilities. This added technical detail to the already known Havex campaign activity.
A cyber-espionage campaign using the Havex remote access trojan was reported as affecting industrial control system and SCADA targets. The activity marked Havex as a threat to operational technology environments.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcenetresec.com
Open sourcesecurityaffairs.co
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.