AdaptixC2 is an open-source command-and-control and post-exploitation framework whose agents are used as remote-access implants in malicious intrusions. It provides listeners and beacon agents for operator-controlled access to compromised systems. Observed deployments use HTTP beaconing and support hands-on post-exploitation, including host and Active Directory reconnaissance, credential dumping, access-token impersonation, privilege escalation, and lateral movement. The framework has been deployed in Windows environments and within attacker-operated Alpine Linux virtual machines.
Customized AdaptixC2 implants have been embedded in trojanized Microsoft Copilot binaries and delivered through multistage loaders, phishing campaigns, ClickFix-derived footholds, and exploitation of internet-facing servers. An education-sector intrusion involving PaperCut MF vulnerabilities CVE-2026-81578 and CVE-2026-82078 used AdaptixC2 to pivot to a domain controller and dump credentials; operators subsequently staged the Active Directory database and supporting registry data for exfiltration. Analyzed variants use encrypted configuration and communications, control-flow obfuscation, API hashing, and runtime resolution of imports and strings to hinder detection and analysis. These modifications are variant-specific rather than universal framework characteristics.
AdaptixC2 is used by multiple unrelated espionage and criminal operators. Associated activity includes SLIME88 phishing against Taiwan’s energy sector, the China-nexus JadeProx cluster’s deployment through TriBack Loader, and Payouts King operations using a concealed Linux virtual machine. Other campaigns have delivered AdaptixC2 through emails impersonating the U.S. Social Security Administration and compromised software packages. Observed targeting includes education, technology, financial technology, energy, and government organizations; its use alone does not establish attribution to a particular threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The initial compromise relied on CVE-2026-81578 and CVE-2026-82078, a pair of vulnerabilities that can be chained to alter settings without authentication and run malicious Java bytecode in the PaperCut server’s security context. | Attackers deployed an AdaptixC2 implant hidden inside a modified Microsoft Copilot binary after exploiting PaperCut MF zero-day vulnerabilities. The implant contacted remote attacker infrastructure and was later used during hands-on post-exploitation activity, including movement to a domain controller.
The initial compromise relied on CVE-2026-81578 and CVE-2026-82078, a pair of vulnerabilities that can be chained to alter settings without authentication and run malicious Java bytecode in the PaperCut server’s security context. | Attackers deployed an AdaptixC2 implant hidden inside a modified Microsoft Copilot binary after exploiting PaperCut MF zero-day vulnerabilities. The implant contacted remote attacker infrastructure and was later used during hands-on post-exploitation activity, including movement to a domain controller.
The attackers exploited CVE-2026-0257, a GlobalProtect authentication bypass, to create VPN sessions without valid user credentials. They scanned hundreds of millions of addresses, filtered promising gateways and fed candidates into an automated exploit loop.
Cisco Talos also identified attacks targeting three additional vulnerabilities within Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20133 (CVSS: 7.5), CVE-2026-20128 (CVSS: 7.5), and CVE-2026-20122 (CVSS: 5.4). All three vulnerabilities were disclosed along with security patches in February 2026. | ...resulting in the deployment of webshell (Godzilla, Behinder, XenShell), Command-and-Control (C2) frameworks (AdaptixC2, Sliver), the XMRig coin miner...
Cisco Talos also identified attacks targeting three additional vulnerabilities within Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20133 (CVSS: 7.5), CVE-2026-20128 (CVSS: 7.5), and CVE-2026-20122 (CVSS: 5.4). All three vulnerabilities were disclosed along with security patches in February 2026. | ...resulting in the deployment of webshell (Godzilla, Behinder, XenShell), Command-and-Control (C2) frameworks (AdaptixC2, Sliver), the XMRig coin miner...
Cisco Talos also identified attacks targeting three additional vulnerabilities within Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20133 (CVSS: 7.5), CVE-2026-20128 (CVSS: 7.5), and CVE-2026-20122 (CVSS: 5.4). All three vulnerabilities were disclosed along with security patches in February 2026. | ...resulting in the deployment of webshell (Godzilla, Behinder, XenShell), Command-and-Control (C2) frameworks (AdaptixC2, Sliver), the XMRig coin miner...
An AdaptixC2 malware payload was also identified, indicating active command-and-control operations. Analysis of exposed payloads shows the attacker used AdaptixC2 for command and control, along with a PowerShell reverse shell.
On Windows systems, the hack of the Telnyx Python SDK resulted in the deployment of an executable named "msbuild.exe" that employs several obfuscation techniques to evade detection and extracts DonutLoader, a shellcode loader, from a PNG image present within the binary to load a full-featured trojan and a beacon associated with AdaptixC2, an open-source command-and-control (C2) framework.
CVE-2026-20182 carries a CVSSv3.1 score of 10.0 (Critical) and is classified under CWE-287: Improper Authentication. The flaw affects the Cisco Catalyst SD-WAN Controller (formerly vSmart)... The peering authentication mechanism is not functioning correctly, allowing an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on the affected system.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SLIME88 has targeted Taiwan’s energy sector through phishing emails and fake certificate installer, attempting to deploy backdoor programs such as AdaptixC2 and CobaltStrike.
The adversary deployed a standard AdaptixC2 framework, including stock listeners, beacon agents, and the base demo agent.
The guest is Alpine Linux 3.22.0 carrying AdaptixC2, Chisel, Rclone, BusyBox and a custom WireGuard traffic obfuscator, and on boot it opens a reverse SSH tunnel out through AdaptixC2 or OpenSSH.
Stage 5: RAT Analysis The final Remote Access Trojan (RAT) is fully import-less. It dynamically resolves both API imports and strings at runtime... This RAT is a variant of AdaptixC2. The AdaptixC2 framework identifies its C2 traffic through the custom HTTP header X-Content-ID, which is part of its default communication profile.
Two observed variants deliver AdaptixC2... Debugging the final payload leads us to AdaptixC2 beacon, an open-source post-exploitation framework.
A new cyber espionage campaign codenamed Operation Dragon Weave has been observed targeting officials and citizens in the Czech Republic and Taiwan to deliver an AdaptixC2 agent... The loader then decrypts and runs the main payload, an AdaptixC2 agent codenamed AZUREVEIL owing to the use of Microsoft Azure Blob Storage for command-and-control (C2).
37 distinct techniques documented for this family, organized by ATT&CK tactic.
Several supported commands allow arbitrary JavaScript to be evaluated in-memory, a capability the threat actors used to download and execute an AdaptixC2 implant.
The evasion loader... employs standard evasion techniques: AES-128-CBC decryption via hardcoded keys/IVs, AMSI/ETW patching, indirect syscalls, anti-sandbox/debugging mechanisms, process injection, and automated self-deletion.
They duplicated the token of a process running as a domain-privileged service account and used it to respawn the implant via CreateProcessAsUser.
Their customized implant used encrypted settings and scrambled program logic to hinder analysis.
When executed, the malicious code in _client.py connects to the attacker’s Command-and-Control (C2) server and downloads a WAV file. This WAV file then drops msbuild.exe and attempts to execute it. The dropped msbuild.exe contains an embedded PNG image used to conceal an obfuscated payload.
[Attackers] deploy[ed] an AdaptixC2 implant hidden inside a modified Microsoft Copilot binary.
The evasion loader... employs standard evasion techniques: AES-128-CBC decryption via hardcoded keys/IVs, AMSI/ETW patching, indirect syscalls, anti-sandbox/debugging mechanisms, process injection, and automated self-deletion.
They duplicated the token of a process running as a domain-privileged service account and used it to respawn the implant via CreateProcessAsUser.
They identified a process running under a domain-privileged service account, copied its access token, and relaunched the implant with that account's rights.
The implant established command-and-control with attacker infrastructure, then went dormant for roughly a day before the threat actors returned to conduct hands-on-keyboard activity.
A scheduled task named TPMProfiler launched qemu-system-x86_64.exe as SYSTEM against a disguised vault.db disk image; operators then worked from the hidden QEMU guest.
The Donut loader component of the shellcode performs reflective loading to execute the final payload entirely in memory... The Donut loader assumes control and carries out a highly sophisticated in-memory reflective loading sequence to inject and execute the RAT.
Threat actors began credential dumping through the implant, beginning with an attempt to dump the process memory of LSASS and saving a copy of the SAM registry hive.
Threat actors attempted to dump the process memory of LSASS and used an NTLM hash recovered during earlier credential dumping.
Threat actors saved a copy of the SAM registry hive during credential dumping.
They identified a process running under a domain-privileged service account, copied its access token, and relaunched the implant with that account's rights.
net group "Domain Admins" /domain was used to enumerate Domain Admins.
It then gathers comprehensive machine and user telemetry before sending the collected data to the Command-and-Control (C2) server via an HTTP POST request
dsquery was used to enumerate active domain computers, while the attack targeted a domain-privileged service account and later collected hashes for domain accounts.
“The attacker also harvested credential-related files and used AdaptixC2 to control at least two Windows server identities.”
The implant uses HTTP for command-and-control communication. The initial HTTP POST request sent to the C2 includes a customized Authorization header and User-Agent.
AdaptixC2... supports multiple communication protocols, including HTTP/S, DNS/DoH, and SMB.
The web shell was used to download a trojanized Microsoft Copilot binary carrying an AdaptixC2 implant from 47.79.64[.]225, then execute it.
258 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
65 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A C2 framework cited as a user-interface inspiration, without discussion of deployment or malicious activity.
An open-source command-and-control framework deployed as a customized, trojanized implant. In this intrusion it was concealed in modified legitimate binaries, used encrypted configuration and obfuscated logic, and supported privileged post-exploitation activity after compromise of an internet-facing PaperCut MF server.
An open-source, modular post-compromise framework customized and embedded in trojanized Microsoft Copilot and PulseSecure-named binaries. In this intrusion, it provided remote shell access, HTTP C2, host/domain discovery, token impersonation, service-based lateral movement, credential harvesting, and support for Active Directory attacks. The implant was obfuscated with control-flow flattening, used hashed API resolution, stored context in PEB fields, and encrypted its C2 configuration and communications.
Go-based command-and-control framework deployed by the operator for HTTP, TCP, and TLS WebSocket communications. The actor used mostly stock components and a custom configuration-generation script.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.