Mythic is an open-source, cross-platform command-and-control and post-exploitation framework used for authorized penetration testing and red-team operations and abused in espionage and financially motivated intrusions. A successor to the macOS-focused Apfell project, it uses a modular architecture that separates its operator interface and server components from extensible agents and communication profiles. It supports payload creation for Windows, Linux, and macOS, collaborative multi-operator campaigns, role-based access, and a web-based management interface.
Mythic provides remote command and script execution, shell access, filesystem interaction, file transfer, reconnaissance, and network scanning. Depending on the selected agent and modules, it supports keylogging, screenshot capture, credential access, token impersonation, process injection, SMB pivoting, and SOCKS proxy chaining. Communication profiles include HTTP/HTTPS, WebSocket, TCP, SMB named pipes, and DNS; custom profiles also use services such as Discord and Cloudflare Queues. Agent implementations support configurable callback intervals and jitter. These capabilities vary by agent rather than being universal properties of every Mythic payload.
Observed deployments include Mythic implants delivered by BLISTER in SOCGHOLISH infection chains and the PowerShell-based QwakMyAgent deployed through remote administration and script loaders after administrator hosts were compromised. Mysterious Werewolf has deployed the Athena agent through spearphishing archives exploiting WinRAR vulnerability CVE-2023-38831, with scheduled-task persistence and Discord-based command delivery. GOFFEE has used custom Mythic agents against technology-sector organizations in Russia and Belarus, including a Linux-container implant executed from anonymous memory without writing an executable to disk. Pakistan-linked SideCopy and APT36 have also used Mythic in espionage operations. The framework is shared across unrelated operators and is not attributable to a single threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ESET researchers have discovered a previously unknown zero-day vulnerability in WinRAR being exploited in the wild by Russia-aligned group RomCom... now assigned CVE-2025-8088: a path traversal vulnerability, made possible with the use of alternate data streams. | Successful exploitation attempts delivered various backdoors used by the RomCom group, specifically a SnipBot variant, RustyClaw, and the Mythic agent.
Three Attack Variants Observed GrimResource (CVE-2025-26633): XSS via apds.dll res:// protocol handler
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Pakistan-linked threat actors SideCopy and APT36 (also known as Transparent Tribe) are actively conducting sophisticated cyber espionage campaigns ... leveraging ... advanced Mythic Command and Control (C2) frameworks for persistent network access and data exfiltration operations.
The Pakistan-linked threat actors SideCopy and APT36 (also known as Transparent Tribe) are actively conducting sophisticated cyber espionage campaigns ... leveraging ... advanced Mythic Command and Control (C2) frameworks for persistent network access and data exfiltration operations.
GOFFEE utilized legitimate utilities and the Mythic agent to conduct reconnaissance, access credentials, and carry out follow-up activities in container environments.
Successful exploitation attempts delivered various backdoors used by the RomCom group, specifically a SnipBot variant, RustyClaw, and the Mythic agent.
"Three minutes prior to the delivery of RomCom’s shellcode loader, the operator tests the connection to Mythic C2."
ShadowSyndicate continues to be associated with toolkits including Cobalt Strike, Metasploit, Havoc, Mythic, Sliver, AsyncRAT, MeshAgent, and Brute Ratel.
38 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Matrix: This MITRE ATT&CK Matrix is a summary of the combined capabilities of every Mythic agent (Apollo, Athena, Tetanus, etc.): Technique Technique ID Observable Scheduled Task/Job T1053
“Flag unexpected scheduled tasks ... pointing to binaries in temp or user directories. These are common persistence mechanisms for Mythic agents.”
MITRE ATT&CK Matrix: This MITRE ATT&CK Matrix is a summary of the combined capabilities of every Mythic agent (Apollo, Athena, Tetanus, etc.): Technique Technique ID Observable Scheduled Task/Job T1053
“Flag unexpected scheduled tasks ... pointing to binaries in temp or user directories. These are common persistence mechanisms for Mythic agents.”
MITRE ATT&CK Matrix: This MITRE ATT&CK Matrix is a summary of the combined capabilities of every Mythic agent (Apollo, Athena, Tetanus, etc.): Technique Technique ID Observable Scheduled Task/Job T1053
“Flag unexpected scheduled tasks ... pointing to binaries in temp or user directories. These are common persistence mechanisms for Mythic agents.”
“On Windows targets, watch for process injection and LSASS access from non-system processes. Apollo, Mythic’s primary Windows agent, uses standard injection techniques.”
Observed adversary tactics and techniques lists "Process Injection: Process Hollowing"; the article also depicts "MYTHIC running inside injected WerFault process."
“Credential access and post-exploitation through agent-side modules for ... token impersonation.”
"We needed a build-time obfuscation pass that could handle the entire binary programmatically, consistently, and repeatably." The custom pipeline renamed symbols, rewrote metadata, encrypted strings, injected dead code, flattened control flow, and removed build artifacts.
"The solution was to rip out Costura entirely and replace it with ILRepack. ILRepack merges multiple assemblies into a single binary at the IL level... One merged assembly going into the obfuscator means one consistent rename pass across all types."
“Steganography scripts (stego_roundtrip.py, discord_fix2/stego.py) ... sit alongside Mythic tasking scripts.”
“telemetry-update[.]services ... with a spoofed Server: NetDNA-cache/2.2 header ... mimics a CDN edge node” and was “built to blend with Windows telemetry traffic.”
“On Windows targets, watch for process injection and LSASS access from non-system processes. Apollo, Mythic’s primary Windows agent, uses standard injection techniques.”
Observed adversary tactics and techniques lists "Process Injection: Process Hollowing"; the article also depicts "MYTHIC running inside injected WerFault process."
“Credential access and post-exploitation through agent-side modules for ... token impersonation.”
“Payload generation with configurable obfuscation, sleep jitter, and kill-date parameters.”
“Modular transport profiles (HTTP/HTTPS, WebSocket, TCP, SMB named pipes, DNS) switchable without redeploying agents.”
“Modular transport profiles (HTTP/HTTPS, WebSocket, TCP, SMB named pipes, DNS) switchable without redeploying agents.”
“Lateral movement support through SMB pipe-based agent pivoting and SOCKS proxy chaining.”
Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).
“Seven Discord diagnostic scripts ... indicate Discord is a production C2 transport, not an experiment.”
141 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
65 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The framework extended by the author's open-source Cloudflare Queues profile. A Worker fronts asynchronous queues and authenticates requests with a shared-secret header. Multipart messages are reassembled, and implants contain no Cloudflare credentials that would expose the backend.
Open-source, cross-platform collaborative command-and-control and post-exploitation framework. It supports modular agents and transports, interactive command execution, file transfer, credential access modules, pivoting, payload generation, and multi-operator web-based campaign management.
Agent used for reconnaissance, credential access, and follow-up activity in container environments.
Modular C2 framework discussed as a comparable tool to Sliver. It separates the control panel from agents and can build custom agents with unique network profiles.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.