Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
MalwareRansomwareUsed by 5 actorsExploits 6 CVEs

AdaptixC2

AdaptixC2 is an open-source post-exploitation and adversarial emulation command-and-control framework used by penetration testers and increasingly abused by threat actors in real-world intrusions. The provided content describes it as a Go-based C2/teamserver with Beacon and Gopher agent families, supporting Windows, Linux, and macOS, multiple transports including HTTP/S, DNS/DoH, SMB named pipes, and raw TCP, and capabilities such as remote shell/command execution, file transfer, data exfiltration, port forwarding, SOCKS proxying, process management, screenshot capture, and in-memory execution of Beacon Object Files. Beacon payloads can be generated as EXE, DLL, service executables, and raw shellcode for x86 and x64 architectures. AdaptixC2 configurations are RC4-encrypted and can be extracted from samples; default agent watermarks noted in the content are be4c0149 for Beacon and 904e5493 for Gopher.

The framework is readily fingerprintable when deployed with default or near-default settings. Version 1.2 ships branded unauthenticated HTTP headers including "Server: AdaptixC2" and "Adaptix-Version: v1.2", and a default 404 page containing "AdaptixC2 404" and "You need to enter the correct connection details." The content also notes JARM/TLS fingerprinting and a commonly observed default OpenSSL self-signed certificate with subject "C=AU, ST=Some-State, O=Internet Widgits Pty Ltd." Common observed ports include teamserver port 4321 and beacon listener port 43211.

Across the cited reporting, AdaptixC2 was used in multiple intrusion types. Unit 42 observed infections in early May 2025, including Microsoft Teams social-engineering and Quick Assist-based access followed by multi-stage PowerShell loaders, in-memory shellcode execution, DLL hijacking with msimg32.dll, and persistence via startup-folder shortcuts or a Run key named "Updater." In those cases, operators used AdaptixC2 for reconnaissance and post-compromise control; one beacon communicated with tech-system[.]online over HTTPS on port 443 using POST /endpoint/api and header X-App-Id. Seqrite reported Operation Dragon Weave, a China-aligned espionage campaign targeting officials and citizens in the Czech Republic and Taiwan across government, research, academic, technology, and financial sectors, where spear-phishing ZIP archives led through LNK/PowerShell or Rust dropper chains, DLL sideloading, and a Rust loader named RUSTCLOAK to an AdaptixC2 agent called AZUREVEIL that used Microsoft Azure Blob Storage as a dead-drop C2 channel and supported 36 commands.

The content also ties AdaptixC2 to ransomware and financially motivated activity. GOLD ENCOUNTER/PayoutsKing used AdaptixC2 or OpenSSH to establish SSH backdoors after initial access via Cisco or SonicWall SSL VPNs, a SolarWinds Web Help Desk vulnerability, or Teams vishing. Sophos reported a fake Claude AI campaign using DLL sideloading and DonutLoader, with a March 2026 sample deploying AdaptixC2-related shellcode and noting the framework had been seen in ransomware attacks. Cisco Talos observed malware agents compiled from the public AdaptixC2 framework during exploitation of Cisco SD-WAN vulnerabilities, alongside webshells, Sliver, XMRig, credential stealers, and other tooling. Ctrl-Alt-Intel reported an unknown actor exploiting CVE-2026-41940 in cPanel/WHM and a custom Indonesian defense-portal exploit chain, deploying an ELF AdaptixC2 payload named "1" configured to beacon to delicate-dew.serveftp[.]com:4455, with telemetry linking the C2 to 95.111.250[.]175. Sophos also documented QEMU-based hidden-VM tradecraft in STAC4713/PayoutsKing intrusions where the guest image used AdaptixC2 or OpenSSH to establish reverse SSH tunnels.

Additional high-confidence indicators and artifacts mentioned in the content include exposed AdaptixC2 infrastructure at 2.26.229[.]254 serving BeaconHTTP on port 4433, GopherTCP on port 4455, and payloads on port 7000; exposed files install.sh, timesync.bin, svhost.exe, svc_timesync.x64.exe, and agent.x86.exe; install.sh SHA256 479b7abd5df2f6ab3de8c32a36478c15012dbc8217f9fa825fd4b9cb7e9b8d13; a hardcoded SSH public key for user timesync-manager; Windows Beacon callbacks to hxxp://2.26.229[.]254:4433 using URIs /api/v1/status, /updates/check.php, and /content.html with header X-ISS and RC4 key 1baccab4cbd2b84f6bc54bf8e6551f93; Cluster 5 Talos activity using filename systemd-resolved with C2 194[.]163[.]175[.]135:4445; and the Indonesian campaign ELF payload hash 1CFEADF01D24182362887B7C5F683E8BDB0E84CDDCE03E3B7564B2D9AB5D15CF. The content repeatedly emphasizes that AdaptixC2 is dual-use tooling, so presence alone does not establish malicious intent, but it is clearly being operationalized by espionage, ransomware, and opportunistic intrusion actors.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

6 CVES
CVE-2026-41940cPanel & WHM Authentication Bypass via Session-File CRLF InjectionExploited in the wild

An AdaptixC2 malware payload was also identified, indicating active command-and-control operations. Analysis of exposed payloads shows the attacker used AdaptixC2 for command and control, along with a PowerShell reverse shell.

via security affairssecurityaffairs.com
CVE-2026-33634Trivy supply chain compromise via malicious release and retagged GitHub ActionsExploited in the wild

On Windows systems, the hack of the Telnyx Python SDK resulted in the deployment of an executable named "msbuild.exe" that employs several obfuscation techniques to evade detection and extracts DonutLoader, a shellcode loader, from a PNG image present within the binary to load a full-featured trojan and a beacon associated with AdaptixC2, an open-source command-and-control (C2) framework.

via the hacker newsthehackernews.com
CVE-2026-20122Arbitrary File Overwrite in Cisco Catalyst SD-WAN Manager APIExploited in the wild

The tools deployed by these clusters range from webshells (Godzilla, Behinder, XenShell) and red team frameworks (AdaptixC2, Sliver) to cryptocurrency miners (XMRig) and credential stealers targeting admin hashes, JWT tokens and AWS credentials.

via tenable blogtenable.com
CVE-2026-20133Information Disclosure in Cisco Catalyst SD-WAN Manager vshellExploited in the wild

The tools deployed by these clusters range from webshells (Godzilla, Behinder, XenShell) and red team frameworks (AdaptixC2, Sliver) to cryptocurrency miners (XMRig) and credential stealers targeting admin hashes, JWT tokens and AWS credentials.

via tenable blogtenable.com
CVE-2026-20128Information Disclosure in Cisco Catalyst SD-WAN Manager DCAExploited in the wild

The tools deployed by these clusters range from webshells (Godzilla, Behinder, XenShell) and red team frameworks (AdaptixC2, Sliver) to cryptocurrency miners (XMRig) and credential stealers targeting admin hashes, JWT tokens and AWS credentials.

via tenable blogtenable.com
CVE-2026-20182Authentication Bypass in Cisco Catalyst SD-WAN Peering AuthenticationExploited in the wild

CVE-2026-20182 carries a CVSSv3.1 score of 10.0 (Critical) and is classified under CWE-287: Improper Authentication. The flaw affects the Cisco Catalyst SD-WAN Controller (formerly vSmart)... The peering authentication mechanism is not functioning correctly, allowing an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on the affected system.

via cyberthronethecyberthrone.in
THREAT ACTORS

Groups observed using it

5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
NegativeGlimmer

A new cyber espionage campaign codenamed Operation Dragon Weave has been observed targeting officials and citizens in the Czech Republic and Taiwan to deliver an AdaptixC2 agent... The loader then decrypts and runs the main payload, an AdaptixC2 agent codenamed AZUREVEIL owing to the use of Microsoft Azure Blob Storage for command-and-control (C2).

via the hacker newsthehackernews.com
GOLD ENCOUNTER

The group has also used a DLL sideloading technique to launch the Havoc C2 post-exploitation framework, and establishes an SSH backdoor via AdaptixC2 or OpenSSH.

via sophos othersophos.com
TeamPCP

83.142.209[.]11 is shown below, confirming ASN membership, TeamPCP attribution, and the AdaptixC2 malware classification.

via huntio bloghunt.io
STAC4713

The March sample is markedly different... the decryption of a .log file culminating in the execution of AdaptixC2-related shellcode. (AdaptixC2 is an open-source red-teaming framework that we’ve seen used in ransomware attacks...)

via sophos blogsophos.com
UNG0902

...DUPERUNNER ... finally executes the Adaptix C2 Beacon...

via seqrite comseqrite.com
MITRE ATT&CK

Techniques & procedures

40 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1566PhishingEvidence1

attackers used phishing attacks to impersonate IT support personnel (using subject lines like “Help Desk (External) | Microsoft Teams”). This convinced employees to initiate legitimate remote assistance sessions using tools like the Quick Assist Remote Monitoring and Management (RMM) tool.

T1566.001Spearphishing AttachmentEvidence1

The activity entails distributing spear-phishing emails containing ZIP attachments to trigger an infection chain that uses a Rust loader to drop the final payload for data exfiltration and remote control.

Execution

8 techniques
T1053.003CronEvidence1

Inside the VM, persistence and a command and control channel were established through the root crontab that launched two scripts at boot

T1059Command and Scripting InterpreterEvidence2

In another case, threat actors deployed a PowerShell script that was designed to deploy AdaptixC2 beacons.

T1059.001PowerShellEvidence1

The attackers deployed the AdaptixC2 beacon using a multi-stage PowerShell loader that downloads an encoded and encrypted payload from a link to a legitimate service.

T1059.004Unix ShellEvidence1

Inside the VM, persistence and a command and control channel were established through the root crontab that launched two scripts at boot... @reboot /bin/sh /sbin/syslogda.sh>/dev/null 2>&1 @reboot /bin/sh /sbin/syslogdb.sh>/dev/null 2>&1

T1106Native APIEvidence1

Запускаемый файл расшифровывает встроенный шелл-код, после чего выделяет память и запускает вредоносную нагрузку с помощью WinAPI-функции CreateThread.

T1204.002Malicious FileEvidence1

One infection sequence begins when the recipient of the ZIP archive opens a malicious Windows Shortcut (LNK) file that masquerades as a PDF document.

T1569.002Service ExecutionEvidence1

Of these, AdaptixC2 supports PsExec and WinRM.

T1574.001DLLEvidence1

This deployment was done both through in-memory shellcode injection and using a file-based DLL hijacking persistence mechanism... The script targets the APPDATA\Microsoft\Windows\Templates directory for DLL hijacking, using msimg32.dll.

Persistence

2 techniques
T1053.003CronEvidence1

Inside the VM, persistence and a command and control channel were established through the root crontab that launched two scripts at boot

T1547.001Registry Run Keys / Startup FolderEvidence1

The script creates a registry entry in the run key named “Updater,” with a PowerShell command that executes the loader.ps1 script. | To guarantee the malicious process automatically starts after reboot, the script creates a shortcut in the startup folder.

Privilege Escalation

3 techniques
T1053.003CronEvidence1

Inside the VM, persistence and a command and control channel were established through the root crontab that launched two scripts at boot

T1055Process InjectionEvidence2

A common technique for achieving this is injecting malicious code into the address space of a legitimate process. Consequently, the payload executes under the identity of a trusted system or user process...

T1547.001Registry Run Keys / Startup FolderEvidence1

The script creates a registry entry in the run key named “Updater,” with a PowerShell command that executes the loader.ps1 script. | To guarantee the malicious process automatically starts after reboot, the script creates a shortcut in the startup folder.

Stealth

7 techniques
T1027Obfuscated Files or InformationEvidence1

Additionally, threat actors can modify and enhance the agent using custom obfuscation, anti-analysis and evasion techniques, making it a continuously evolving threat.

T1027.011Fileless StorageEvidence1

This fileless approach significantly reduces the attacker’s footprint on the system.

T1055Process InjectionEvidence2

A common technique for achieving this is injecting malicious code into the address space of a legitimate process. Consequently, the payload executes under the identity of a trusted system or user process...

T1140Deobfuscate/Decode Files or InformationEvidence1

Once downloaded, the PowerShell script decrypts the payload using a simple XOR key.

T1497Virtualization/Sandbox EvasionEvidence1

adversaries leveraging QEMU, an open-source machine emulator and virtualizer typically used for development and testing, to deploy virtual machines that contained and executed malicious payloads. This approach enabled them to maintain covert access and bypass host-based detection from AV and EDR solutions.

T1574.001DLLEvidence1

This deployment was done both through in-memory shellcode injection and using a file-based DLL hijacking persistence mechanism... The script targets the APPDATA\Microsoft\Windows\Templates directory for DLL hijacking, using msimg32.dll.

T1620Reflective Code LoadingEvidence1

Instead of writing the decrypted payload to disk... the script leverages .NET capabilities to allocate memory within the PowerShell process itself. The script then copies the decrypted payload, which is actually shellcode, into this allocated memory region.

Credential Access

5 techniques
T1003.001LSASS MemoryEvidence1

In addition, to gain access to credentials, an attacker may attempt to extract sensitive information directly from the memory of the lsass.exe process.

T1555Credentials from Password StoresEvidence2

The teamserver exposes a full REST and WebSocket API for operator control — credential management... /creds/list GET List harvested credentials

T1555.003Credentials from Web BrowsersEvidence1

KEDR Expert detects this activity using the credentials_from_web_browsers rule.

T1558Steal or Forge Kerberos TicketsEvidence1

Furthermore, credential acquisition also strongly relies on attacks on the Kerberos protocol... AdaptixC2 supports specialized modules designed to exploit specific features of the Kerberos protocol.

T1558.004AS-REP RoastingEvidence1

KEDR Expert detects this behavior via the possible_asreproasting_via_preauth_value rule.

Discovery

4 techniques
T1016System Network Configuration DiscoveryEvidence1

This included discovery commands such as nltest.exe, whoami.exe and ipconfig.exe.

T1033System Owner/User DiscoveryEvidence1

This included discovery commands such as nltest.exe, whoami.exe and ipconfig.exe.

T1482Domain Trust DiscoveryEvidence1

This included discovery commands such as nltest.exe, whoami.exe and ipconfig.exe.

T1497Virtualization/Sandbox EvasionEvidence1

adversaries leveraging QEMU, an open-source machine emulator and virtualizer typically used for development and testing, to deploy virtual machines that contained and executed malicious payloads. This approach enabled them to maintain covert access and bypass host-based detection from AV and EDR solutions.

Lateral Movement

4 techniques
T1021Remote ServicesEvidence1

This convinced employees to initiate legitimate remote assistance sessions using tools like the Quick Assist Remote Monitoring and Management (RMM) tool.

T1021.002SMB/Windows Admin SharesEvidence1

To establish communication between agents via the SMB protocol, the framework utilizes named pipes.

T1021.004SSHEvidence1

The script syslogdb.sh maintained an SSH connection to the C2 server over TCP 443 and forwarded local port 33443 to the C2 server through this tunnel.

T1021.006Windows Remote ManagementEvidence1

Let’s examine the lateral movement detection techniques using the exploitation of the WinRM (Windows Remote Management) service as a primary example.

Collection

1 technique
T1113Screen CaptureEvidence1

The teamserver exposes a full REST and WebSocket API for operator control — credential management, agent tasking, screenshot capture... /screen/image GET Retrieve a screenshot image

Command and Control

9 techniques
T1071Application Layer ProtocolEvidence3

AdaptixC2 is an open-source post-exploitation framework... The framework ships two agent families... listeners as loadable plugins (“extenders”) covering HTTP/S, DNS/DoH, SMB named pipes, and raw TCP transports. | BeaconHTTP : HTTP/S callback with configurable URIs, headers, and User-Agent rotation... BeaconDNS : DNS-based callback channel... BeaconTCP : Bind-style TCP channel for internal pivots

T1071.001Web ProtocolsEvidence2

BEACON_HTTP for web-based communication... The beacon then established communication with a remote server, enabling the threat actors to obtain C2 on the infected machine.

T1071.004DNSEvidence1

AdaptixC2 supports the transmission of data and commands from C2 via both traditional DNS over UDP and DNS over HTTPS (DoH). This communication method enables the masking of the communication channel between the agent and the server.

T1090ProxyEvidence1

the framework supports sophisticated tunneling capabilities, including SOCKS4/5 proxy functionality and port forwarding.

T1090.001Internal ProxyEvidence1

/tunnel/start/lportfwd POST Start a local port forward | /tunnel/start/socks5 POST Start a SOCKS5 proxy tunnel

T1090.002External ProxyEvidence1

the beacon’s local traffic was carried over the encrypted SSH channel to remote infrastructure, enabling command-and-control communication while blending into normal outbound traffic.

T1090.003Multi-hop ProxyEvidence1

Internal (P2P): agents communicate with adjacent agents, establishing a chain back to a host that interfaces directly with the C2 server. This approach leverages TCP and SMB.

T1105Ingress Tool TransferEvidence4

The script downloads a Base64-encoded shellcode payload from a remote server using Invoke-RestMethod. The downloaded content is then decoded.

T1572Protocol TunnelingEvidence1

To implement Beacon DNS, the AdaptixC2 agent also supports the DNS over HTTPS (DoH) protocol. This mechanism encapsulates standard DNS queries within HTTP messages transmitted over a secure TLS connection.

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence2

Even when an agent employs advanced evasion, masking, or obfuscation techniques on the endpoint, it must maintain a connection with its C2 server to receive commands, exfiltrate results, and coordinate subsequent attack stages.

INDICATORS OF COMPROMISE

IOCs tracked for this family

108 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
67 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
37 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
4 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app3 days ago
uri●●●●●●●●●●●●View more in app3 days ago
cidr.v4●●●●●●●●●●●●View more in app10 days ago
domain●●●●●●●●●●●●View more in app10 days ago
hash.sha256●●●●●●●●●●●●View more in app10 days ago
ip.v4●●●●●●●●●●●●View more in app10 days ago
ACTIVITY FEED

Recent activity

37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

censys blogNews
Jun 17, 2026
AdaptixC2: Fingerprinting an Open-Source C2 Framework at Scale - Censys

Open-source post-exploitation command-and-control framework written in Go and C++/Qt, used after initial compromise for maintaining access, tasking agents, lateral movement, data collection, screenshot capture, tunneling, and multi-operator collaboration. It supports multiple listener transports including HTTP/S, DNS/DoH, SMB named pipes, and raw TCP.

Read more
securelist ruNews
Jun 8, 2026
Хактивисты выходят за рамки политически мотивированных атак | Securelist

Open-source post-exploitation framework whose observed agents were packed beacons delivered through a custom x64 loader. The beacon decrypts shellcode, launches a DLL agent with RC4-encrypted configuration, and supports command execution, file operations, process control, program launch, SOCKS port forwarding, and BOF modules.

Read more
the hacker newsNews
Jun 1, 2026
China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan

A post-compromise espionage implant that uses Azure Blob Storage as a dead-drop C2 channel. It supports 36 commands for file operations, uploads/downloads, shell execution, process control, port forwarding, SOCKS proxy control, C2 management, and in-memory BOF execution, giving attackers broad remote control and data exfiltration capability.

Read more
tenable blogNews
May 15, 2026
CVE-2026-20182: Cisco SD-WAN Active Exploitation | Tenable®

A red team command-and-control framework deployed by threat clusters exploiting Cisco SD-WAN devices.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching108

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution5

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities6

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping40

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.