Wan, Y. (2025, March 3). Havoc: SharePoint with Microsoft Graph API turns into FUD C2. Retrieved August 4, 2025.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1033 System Owner/User Discovery |
MalwareHavoc | Havoc can trigger exection of `whoami` on the target host to display the current user. |
| T1057 Process Discovery |
MalwareHavoc | Havoc can enumerate processes on targeted hosts. |
| T1071.001 Web Protocols |
MalwareHavoc | Havoc can use HTTP/S listeners to establish and maintain C2 communications. |
| T1082 System Information Discovery |
MalwareHavoc | Havoc can gather system information including hostname, domain, and OS details. |
| T1087 Account Discovery |
MalwareHavoc | Havoc can identify privileged user accounts on infected systems. |
| T1204.004 Malicious Copy and Paste |
MalwareHavoc | The Havoc infection chain has been initiated via ClickFix lures in phishing emails. |
| T1566.002 Spearphishing Link |
MalwareHavoc | Havoc has been distributed through ClickFix phishing campaigns. |
| T1573.001 Symmetric Cryptography |
MalwareHavoc | Havoc can send an AES encrypted check-in request to the C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.