Merlin is an open-source command-and-control and post-exploitation framework written in Go and first published in 2017. Its agent can be compiled for Windows, Linux, and macOS and is abused as a backdoor in espionage operations. Merlin supports HTTP/1.1, HTTP/2, and HTTP/3 over QUIC communications, and agents compatible with the Mythic framework have also been deployed by attackers.
Merlin provides remote command execution and host profiling, including collection of operating-system, hostname, username, architecture, network, and process information. Its functionality can be extended through external offensive-tool modules. These can download and execute PowerShell tools such as Invoke-Mimikatz for credential access or retrieve, compile, and execute Seatbelt for reconnaissance. Observed agents have used AES-encrypted command-and-control traffic and downloaded additional payloads, including Loki 2.0.
Attackers have deployed Merlin through DLL side-loading of legitimate applications and established persistence using registry and service mechanisms. A Russian campaign used targeted phishing emails impersonating human-resources personnel, nested archives, a malicious shortcut, and PowerShell to launch an agent disguised as an image while displaying a decoy résumé. That chain used a legitimate Windows console utility for indirect, headless execution.
Merlin has been used by Tropic Trooper, the Mythic Likho activity cluster, and the Chinese state-aligned Cluster Alpha intrusion set tracked as STAC1248. Documented targets include a Southeast Asian government organization and Russian industrial and telecommunications-related companies. Its public availability and use by multiple unrelated operators make its presence insufficient for threat-actor attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Deployment of the Merlin Agent ... and the Pinkman Agent was performed in a similar manner as the same side-loading chain including vmnat.exe and shfolder.dll was used.”
Mythic Likho (Arcane Werewolf) ... Merlin agent (Go), совместимый с фреймворком Mythic
...has been used in the past to fetch next-stage payloads like Cobalt Strike Beacon or Merlin agent for the Mythic framework.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
attackers need to take advantage of techniques more similar to those we see in Windows systems, such as Cron Jobs
attackers need to take advantage of techniques more similar to those we see in Windows systems, such as Cron Jobs
...переименовывает файл 3(1).jpg в Rez_ZelibRV.pdf... запускает бэкдор Merlin из файла 19.jpg...
the HUI loader (msedge_elf.dll), which de-obfuscated the file log.ini to reveal a Cobalt Strike reflective Loader
Cross-platform post-exploitation HTTP Command & Control agent written in golang ... This implementation uses Mythic's Default HTTP Command and Control profile
This implementation uses Mythic's Default HTTP Command and Control profile
Many frameworks can utilize external tools as modules Pattern Download external tools • Merlin
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Go-based remote access agent compatible with the Mythic framework.
A post-exploitation agent for the Mythic framework referenced as a payload previously fetched in Tropic Trooper activity.
An open-source Golang command-and-control agent deployed via vmnat.exe DLL sideloading to establish persistence and communicate with attacker infrastructure.
Открытый исходный постэксплуатационный агент/бэкдор на Go для Windows, Linux и macOS. В данном случае используется для скрытого запуска, связи с C2 по HTTP(S), шифрования трафика AES, сбора системной информации и дальнейшей загрузки других полезных нагрузок, включая Loki 2.0.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.