Havoc

S1229

Malware.View on attack.mitre.org

About this malware

Havoc is an open-source post-exploitation command and control (C2) framework first released on GitHub in October 2022 by C5pider (Paul Ungur), who continues to maintain and develop it with community contributors. Havoc provides a wide range of offensive security capabilities and has been adopted by multiple threat actors to establish and maintain control over compromised systems.

Techniques used29

Procedure examples29

TechniqueProcedure example
T1005
Data from Local System

Havoc can download files from the victim's computer.

T1016
System Network Configuration Discovery

Havoc has a module for network enumeration including determining IP addresses.

T1016.001
Internet Connection Discovery

The Havoc demon can check for a connection to the C2 server from the target machine.

T1018
Remote System Discovery

Havoc features a module capable of host enumeration.

T1027.010
Command Obfuscation

Havoc has utilized XOR encryption with the key “01-01-1900” to obfuscate command strings.

T1033
System Owner/User Discovery

Havoc can trigger exection of `whoami` on the target host to display the current user.

T1055.001
Dynamic-link Library Injection

Havoc has DLL spawn and injection modules.

T1055.002
Portable Executable Injection

Havoc has itself injected into `C:\\Windows\\System32\\Werfault.exe` on targeted systems.

T1057
Process Discovery

Havoc can enumerate processes on targeted hosts.

T1059.001
PowerShell

Havoc can facilitate the execution of PowerShell commands.

T1059.003
Windows Command Shell

Havoc can execute commands via `cmd.exe`.

T1071.001
Web Protocols

Havoc can use HTTP/S listeners to establish and maintain C2 communications.

T1071.002
File Transfer Protocols

Havoc can use an SMB listener for C2 communication.

T1082
System Information Discovery

Havoc can gather system information including hostname, domain, and OS details.

T1083
File and Directory Discovery

The Havoc interface can display a file explorer view of the compromised host.

View all 29 procedure examples

Groups that use it1

Campaigns0

None recorded.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.