Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to malware
MalwareUsed by 2 actorsExploits 4 CVEs

Mythic Agent

Mythic Agent is a post-exploitation implant built on the Mythic C2 framework that provides remote-access capabilities including command execution, reconnaissance, file exfiltration, lateral movement, command-and-control communication, and loading of additional plugins or payloads. The content links it primarily to RomCom activity in 2025, including campaigns where RomCom used SocGholish/FakeUpdates fake browser-update lures to deliver a targeted Mythic Agent loader to a U.S. civil engineering firm with ties to Ukraine-related work, and separate spearphishing campaigns exploiting the WinRAR zero-day CVE-2025-8088 against financial, manufacturing, defense, and logistics organizations in Europe and Canada. In the WinRAR chains, malicious RAR archives dropped LNK and DLL/EXE payloads; one observed chain used Updater.lnk to set HKCU\SOFTWARE\Classes\CLSID{1299CF18-C4F5-4B6A-BB0F-2299F0398E27}\InprocServer32 to %TEMP%\msedge.dll for COM hijacking, after which msedge.dll decrypted embedded AES shellcode and launched the Mythic agent. Arctic Wolf also reported a targeted loader disguised as msedge.dll that executed only when the victim Active Directory domain matched a hardcoded value, and described the shellcode as a Mythic dynamichttp agent. Reported C2 endpoints associated with Mythic Agent activity in the content include https://srlaptop[.]com/s/0.7.8/clarity.js and https://imprimerie-agp[.]com/s/0.7.8/clarity.js. The content also notes Mythic Agent was found among malware on a compromised Microsoft Exchange server in an intrusion likely involving Erudite Mogwai/Space Pirates, and one source associates Mythic Agent with GOFFEE. High-confidence aliases in the provided content are limited to Mythic Agent and mythic_agent.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

4 CVES
CVE-2021-34473ProxyShell pre-auth SSRF in Microsoft Exchange AutodiscoverExploited in the wild

...источником их заражения оказался почтовый сервер Exchange, который оказался скомпрометированным еще летом 2024 года с помощью эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).

via rt solarrt-solar.ru
CVE-2021-34523Microsoft Exchange PowerShell Backend Elevation of Privilege (ProxyShell)Exploited in the wild

...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).

via rt solarrt-solar.ru
CVE-2025-8088WinRAR Windows Path Traversal via NTFS Alternate Data StreamsExploited in the wild

The vulnerability, tracked as CVE-2025-8088, affects all Windows versions of WinRAR up to 7.12 ... a path traversal bug that leverages Window’s alternate data streams (ADS) feature to circumvent normal file extraction safeguards.

via techrepublic com securitytechrepublic.com
CVE-2021-31207Post-auth Arbitrary File Write in Microsoft Exchange Server (ProxyShell)Exploited in the wild

...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).

via rt solarrt-solar.ru
THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
RomCom

In November 2025, Arctic Wolf revealed that SocGholish was being used by the RomCom threat actors to deliver the Mythic Agent, highlighting the use of the initial access broker's services by a broad range of actors with varied motivations.

via the hacker newsthehackernews.com
Paper Werewolf

...были обнаружены различные файлы вредоносного ПО: ... Mythic Agent (GOFFEE)

via rt solarrt-solar.ru
MITRE ATT&CK

Techniques & procedures

8 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1189Drive-by CompromiseEvidence1

SocGholish is a JavaScript (JS)-based downloader malware that's distributed via compromised websites by masquerading as deceptive updates for web browsers like Google Chrome or Mozilla Firefox, and other popular software.

T1190Exploit Public-Facing ApplicationEvidence1

«…источником их заражения оказался почтовый сервер Exchange, который оказался скомпрометированным еще летом 2024 года с помощью эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).»

Execution

2 techniques
T1059Command and Scripting InterpreterEvidence1

The backdoor used by the group is capable of executing commands and downloading additional modules to the victim’s machine.

T1203Exploitation for Client ExecutionEvidence1

ESET researchers have discovered a previously unknown zero-day vulnerability in WinRAR being exploited in the wild by Russia-aligned group RomCom... The vulnerability, CVE-2025-8088, is a path traversal vulnerability... Disguised as an application document, the weaponized archives exploited a path traversal flow to compromise its targets.

Privilege Escalation

1 technique
T1055Process InjectionEvidence1

PowerTaskel загружает бинарный агент с командного сервера, внедряет его в память своего процесса и запускает в отдельном потоке

Stealth

3 techniques
T1055Process InjectionEvidence1

PowerTaskel загружает бинарный агент с командного сервера, внедряет его в память своего процесса и запускает в отдельном потоке

T1564.004NTFS File AttributesEvidence1

The vulnerability, CVE-2025-8088, is a path traversal vulnerability, which is made possible via the use of alternate data streams.

T1620Reflective Code LoadingEvidence1

Третий скрипт отвечает за выделение памяти, загрузку шелл-кода из HTA-файла ... и передачу управления загруженному шелл-коду

Command and Control

1 technique
T1105Ingress Tool TransferEvidence2

Orange Cyberdefense said it has observed SocGholish infections delivering loaders like Gholoader and MintsLoader, which, in turn, lead to the deployment of additional payloads like GhostWeaver, LockBit, AsyncRAT, and NetSupport RAT.

INDICATORS OF COMPROMISE

IOCs tracked for this family

3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Hashes
3 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.md5●●●●●●●●●●●●View more in app1 year ago
hash.sha256●●●●●●●●●●●●View more in app1 year ago
hash.sha1●●●●●●●●●●●●View more in app1 year ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching3

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities4

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping8

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.