Adaptix C2 is a command-and-control framework observed in both Internet-exposed multi-framework environments and malicious operations. It has been used as command-and-control infrastructure in Operation DUPEHIKE, which targeted Russian human-resources personnel with bonus-themed lures and delivered the DUPERUNNER malware. JITTERLY, a Linux implant associated with the Red Heron intrusion set, implements a protocol, registration process, configuration structure, and command format closely aligned with an Adaptix C2 Linux agent, including compatibility with the framework’s Gopher protocol. Adaptix C2 has also been observed deployed alongside frameworks including Mythic, Sliver, and Havoc in likely laboratory or training infrastructure. The available information establishes Adaptix C2 as a post-exploitation command-and-control framework, but does not support assigning it a specific malware-family class or a standalone target platform.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
JITTERLY's protocol, configuration fields, registration process, and command structure closely match the Linux agent used by the Adaptix C2 framework.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
“CVE-2020-1472, also known as ZeroLogon, allows for compromising a vulnerable operating system and executing commands as a privileged user.” | “CVE-2021-34527, also known as PrintNightmare… enabling remote access to a vulnerable OS and high-privilege command execution.”
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Framework de commande et contrôle avec lequel JITTERLY est compatible; le contenu ne le décrit pas comme étant déployé ou utilisé directement dans cette campagne.
Command-and-control framework observed alongside Mythic on some hosts, including the assessed multi-framework lab/training cluster.
An open-source post-exploitation command-and-control framework whose Linux Gopher-agent protocol and command mappings are closely compatible with JITTERLY. The content describes Red Heron as relying on it for post-exploitation operations.
Relatively new post-exploitation/C2 framework referenced as being adopted by malicious actors.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.