Threat Advisory

Threat Actors Adopt Havoc Framework for Post-Exploitation in Targeted Attacks

Threat: Malware
Threat Actor Region: USA
Targeted Sector: Government & Defense
Criticality: High
[subscribe_to_unlock_form]

 

Summary:[/subscribe_to_unlock_form]

 

Summary:[emaillocker id="1283"]

Threat actors are using the open-source Havoc’s command-and-control (C2) framework in place of other well-known, respected toolkits. An organization noticed at the start of January 2023 that an unnamed government organization was being targeted by a new campaign. The open-source Havoc framework is a modern post-exploitation command-and-control framework capable of bypassing the latest versions of windows 11 defender. The start of an attack sequence is by using a ZIP archive that includes a screen saver and a lure document that will download and run the Havoc Demon agent on the compromised computer. Demon is an implant created by the Havoc Framework that functions similarly to a Beacon in gaining persistent access and spreading malicious payloads. The server can execute different commands on the target system after successfully installing the Demon on the victim’s system. After that, the results are encrypted and exfiltrated to the C2 server.

 

 

Threat Profile:

Tactic Technique ID Technique
Initial Access T1566 Phishing
Execution T1059 Command and Scripting Interpreter
T1204 User Execution
Persistence T0889 Modify Program
Privilege Escalation T1548 Abuse Elevation Control Mechanism
Defense Evasion T1055 Process Injection
T1027 Obfuscated Files or Information
T1140 Deobfuscate/Decode Files or Information
Command and Control T1105 Ingress Tool Transfer
Impact T1486 Data Encrypted for Impact

 

References:

The following reports contain further technical details:

https://thehackernews.com/2023/02/threat-actors-adopt-havoc-framework-for.html

[/emaillocker]
crossmenu