Havoc is an open-source command-and-control and post-exploitation framework used for adversary emulation and abused in espionage and ransomware intrusions. Its implementation includes Go, C++, and Qt components, and its endpoint agents are known as Demons. Observed deployments target Windows systems. The framework supports file operations, process injection, and credential access, with HTTP(S) command-and-control communications and configurable beacon timing and jitter.
Havoc payloads have been deployed through DLL side-loading involving legitimate executables, shellcode loaders, PowerShell-based loading, and dedicated injection utilities. Spearphishing campaigns exploiting the WinRAR path traversal vulnerability CVE-2025-8088 have delivered Havoc as follow-on tooling after an initial loader. Other deployments use scheduled tasks to launch loaders and maintain access. Havoc Demons have also been bundled with utilities that exploit vulnerable drivers; those utilities' privilege-escalation and security-tampering functions are distinct from the embedded Havoc agent.
Observed users include SloppyLemming, also tracked as OUTRIDER TIGER; Bitter, also tracked as TA397; Lemon Sandstorm; and the Payouts King ransomware operation. These deployments span South Asian government and defense espionage, Middle Eastern critical infrastructure intrusions, and attacks against commercial organizations. Havoc is shared tooling rather than an implant exclusive to any single threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Multiple intrusion sets have been observed actively exploiting CVE-2025-8088, a path traversal vulnerability in WinRAR, to establish initial access and deploy modular malware frameworks. Affected software: WinRAR prior to version 7.13.
The ktool.exe payload follows the same idea as the previously reported one: installing and exploiting the iQVW64.sys vulnerable driver (CVE-2015-2291) via BYOVD and deploying a Havoc Demon payload.
Around the same time, Check Point also reported that another high-severity security flaw in the TrueConf client (CVE-2026-3502) was exploited in the wild as a zero-day as part of a campaign targeting government entities in Southeast Asia to deploy the Havoc C2 framework. | Check Point also reported that another high-severity security flaw in the TrueConf client (CVE-2026-3502) was exploited in the wild as a zero-day as part of a campaign targeting government entities in Southeast Asia to deploy the Havoc C2 framework.
Researchers at Sophos recently discovered that in mid-2025, Bronze Butler (a.k.a. Tick, RedBaldKnight, Stalker Panda, Swirl Typhoon) exploited a critical vulnerability in Lanscope when it was still a zero-day... Motex disclosed a vulnerability designated CVE-2025-61932... Motex has released a fix... CISA added CVE-2025-61932 to its Known Exploited Vulnerabilities (KEV) catalog.
22 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The actor predominantly relies on open source adversary emulation frameworks, such as Cobalt Strike, Havoc, and others.
After dropping QEMU, the operators sideloaded a Havoc C2 payload named vcruntime140_1.dll beside a legitimate ADNotificationManager.exe.
Variantes observées par la CTU : Havoc — acronis.exe, hwaudkiller.exe, sophos.exe, Sophos2.exe, Sophos3.exe.
Variante Windows # Basée sur le framework Havoc avec des capacités post-exploitation personnalisées
This executes a Havoc payload. Created using domain administrator account. | The payload component was identified as a Havoc agent.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
139 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
123 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned through a historical infrastructure collection used as an investigation starting point. The content does not describe its capabilities or establish current ownership of the infrastructure.
An offensive framework mentioned only as an inspiration for graphcat's interface.
Command-and-control framework observed on one host in a multi-framework cluster assessed as likely shared lab or training infrastructure.
Outil de neutralisation des EDR observé dans deux intrusions The Gentlemen, avec des exécutables ciblant notamment les processus Sophos EDR.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.