Merlin is an open-source, Go-based post-exploitation command-and-control framework and agent used as a backdoor on compromised systems. First published in 2017, it is cross-platform and can be compiled for Windows, Linux, and macOS. Merlin supports multiple transport options including HTTP/1.1, HTTP/2, and HTTP/3 over QUIC, and is designed to be extensible through modules and external offensive tooling. It has also been used as an agent within the Mythic framework ecosystem.
In intrusion operations, Merlin provides remote access and post-compromise tasking rather than serving as an initial exploit by itself. Documented use includes execution of shell commands, collection of host profiling data, retrieval of follow-on payloads, and operation alongside external tools such as credential access and reconnaissance utilities. Reported tradecraft shows Merlin being used to download or invoke additional offensive modules, including PowerShell-based tooling, and to fetch next-stage payloads such as other implants or commercial red-team frameworks.
Observed campaigns show Merlin delivered through spearphishing lures and archive-based infection chains, including decoy documents and indirect execution methods to disguise the payload. It has also been deployed through DLL sideloading chains that abuse legitimate signed binaries for execution and defense evasion. On Windows, public reporting has documented Merlin-associated persistence attempts using mechanisms such as Run keys, scheduled tasks, and Alternate Data Streams, although some specific implementations have been noted as unreliable.
Merlin has appeared in multiple real-world espionage and post-compromise operations. It has been observed in activity clusters assessed as aligned with Chinese state interests, in campaigns targeting government organizations in Southeast Asia, and in operations against Russian organizations attributed to a cluster dubbed Mythic Likho. Reporting also notes prior use by Tropic Trooper in campaigns targeting East Asian victims before a later tooling shift. Victimology associated with Merlin use includes government, telecom, defense-related, industrial, and other enterprise environments.
Because Merlin is publicly available and modular, it is used both legitimately for adversary emulation and illegitimately by threat actors. In malicious operations it is best characterized as a cross-platform backdoor and post-exploitation agent that enables reconnaissance, persistence, payload delivery, and broader hands-on-keyboard activity after initial compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Mythic Likho (Arcane Werewolf) ... Merlin agent (Go), совместимый с фреймворком Mythic
We observed the first persistence mechanism used in Cluster Alpha in March, when the attacker deployed Merlin, an open-source C2 tool written in Golang.
...has been used in the past to fetch next-stage payloads like Cobalt Strike Beacon or Merlin agent for the Mythic framework.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
attackers need to take advantage of techniques more similar to those we see in Windows systems, such as Cron Jobs
attackers need to take advantage of techniques more similar to those we see in Windows systems, such as Cron Jobs
...переименовывает файл 3(1).jpg в Rez_ZelibRV.pdf... запускает бэкдор Merlin из файла 19.jpg...
the HUI loader (msedge_elf.dll), which de-obfuscated the file log.ini to reveal a Cobalt Strike reflective Loader
Cross-platform post-exploitation HTTP Command & Control agent written in golang ... This implementation uses Mythic's Default HTTP Command and Control profile
This implementation uses Mythic's Default HTTP Command and Control profile
Many frameworks can utilize external tools as modules Pattern Download external tools • Merlin
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Go-based remote access agent compatible with the Mythic framework.
A post-exploitation agent for the Mythic framework referenced as a payload previously fetched in Tropic Trooper activity.
An open-source Golang command-and-control agent deployed via vmnat.exe DLL sideloading to establish persistence and communicate with attacker infrastructure.
Открытый исходный постэксплуатационный агент/бэкдор на Go для Windows, Linux и macOS. В данном случае используется для скрытого запуска, связи с C2 по HTTP(S), шифрования трафика AES, сбора системной информации и дальнейшей загрузки других полезных нагрузок, включая Loki 2.0.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.