ATT&CKReferencesFortinet Havoc MAR 2025

Fortinet Havoc MAR 2025

Wan, Y. (2025, March 3). Havoc: SharePoint with Microsoft Graph API turns into FUD C2. Retrieved August 4, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwareHavoc

Havoc can trigger exection of `whoami` on the target host to display the current user.

T1057
Process Discovery
MalwareHavoc

Havoc can enumerate processes on targeted hosts.

T1071.001
Web Protocols
MalwareHavoc

Havoc can use HTTP/S listeners to establish and maintain C2 communications.

T1082
System Information Discovery
MalwareHavoc

Havoc can gather system information including hostname, domain, and OS details.

T1087
Account Discovery
MalwareHavoc

Havoc can identify privileged user accounts on infected systems.

T1204.004
Malicious Copy and Paste
MalwareHavoc

The Havoc infection chain has been initiated via ClickFix lures in phishing emails.

T1566.002
Spearphishing Link
MalwareHavoc

Havoc has been distributed through ClickFix phishing campaigns.

T1573.001
Symmetric Cryptography
MalwareHavoc

Havoc can send an AES encrypted check-in request to the C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.