Summary:[/subscribe_to_unlock_form]
Summary:[emaillocker id="1283"]
Threat actors are using the open-source Havoc’s command-and-control (C2) framework in place of other well-known, respected toolkits. An organization noticed at the start of January 2023 that an unnamed government organization was being targeted by a new campaign. The open-source Havoc framework is a modern post-exploitation command-and-control framework capable of bypassing the latest versions of windows 11 defender. The start of an attack sequence is by using a ZIP archive that includes a screen saver and a lure document that will download and run the Havoc Demon agent on the compromised computer. Demon is an implant created by the Havoc Framework that functions similarly to a Beacon in gaining persistent access and spreading malicious payloads. The server can execute different commands on the target system after successfully installing the Demon on the victim’s system. After that, the results are encrypted and exfiltrated to the C2 server.

Threat Profile:
| Tactic | Technique ID | Technique |
| Initial Access | T1566 | Phishing |
| Execution | T1059 | Command and Scripting Interpreter |
| T1204 | User Execution | |
| Persistence | T0889 | Modify Program |
| Privilege Escalation | T1548 | Abuse Elevation Control Mechanism |
| Defense Evasion | T1055 | Process Injection |
| T1027 | Obfuscated Files or Information | |
| T1140 | Deobfuscate/Decode Files or Information | |
| Command and Control | T1105 | Ingress Tool Transfer |
| Impact | T1486 | Data Encrypted for Impact |
References:
The following reports contain further technical details:
https://thehackernews.com/2023/02/threat-actors-adopt-havoc-framework-for.html
[/emaillocker]