Shivtarkar, N. and Jain, S. (2023, February 14). Havoc Across the Cyberspace. Retrieved August 4, 2025.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016.001 Internet Connection Discovery |
MalwareHavoc | The Havoc demon can check for a connection to the C2 server from the target machine. |
| T1033 System Owner/User Discovery |
MalwareHavoc | Havoc can trigger exection of `whoami` on the target host to display the current user. |
| T1057 Process Discovery |
MalwareHavoc | Havoc can enumerate processes on targeted hosts. |
| T1071.001 Web Protocols |
MalwareHavoc | Havoc can use HTTP/S listeners to establish and maintain C2 communications. |
| T1071.002 File Transfer Protocols |
MalwareHavoc | Havoc can use an SMB listener for C2 communication. |
| T1113 Screen Capture |
MalwareHavoc | Havoc can capture screenshots. |
| T1497.003 Time Based Checks |
MalwareHavoc | The Havoc demon agent can be set to sleep for a specified time. |
| T1573.001 Symmetric Cryptography |
MalwareHavoc | Havoc can send an AES encrypted check-in request to the C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.