ATT&CKReferencesZscaler Havoc FEB 2023

Zscaler Havoc FEB 2023

Shivtarkar, N. and Jain, S. (2023, February 14). Havoc Across the Cyberspace. Retrieved August 4, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1016.001
Internet Connection Discovery
MalwareHavoc

The Havoc demon can check for a connection to the C2 server from the target machine.

T1033
System Owner/User Discovery
MalwareHavoc

Havoc can trigger exection of `whoami` on the target host to display the current user.

T1057
Process Discovery
MalwareHavoc

Havoc can enumerate processes on targeted hosts.

T1071.001
Web Protocols
MalwareHavoc

Havoc can use HTTP/S listeners to establish and maintain C2 communications.

T1071.002
File Transfer Protocols
MalwareHavoc

Havoc can use an SMB listener for C2 communication.

T1113
Screen Capture
MalwareHavoc

Havoc can capture screenshots.

T1497.003
Time Based Checks
MalwareHavoc

The Havoc demon agent can be set to sleep for a specified time.

T1573.001
Symmetric Cryptography
MalwareHavoc

Havoc can send an AES encrypted check-in request to the C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.