Security analysts have noticed a trend among threat actors shifting towards adopting a novel open-source command and control (C2) framework called Havoc as an alternative to paid solutions like Cobalt Strike and Brute Ratel. Developed in the C language and introduced in 2022, Havoc’s Main branch received updates in 2023. Noteworthy features of Havoc include its cross-platform compatibility and its ability to bypass Microsoft Defender on updated Windows 11 systems through techniques like sleep obfuscation, return address stack spoofing, and indirect syscalls. Similar to other exploitation kits, Havoc offers a broad array of modules, enabling penetration testers (and malicious actors) to carry out diverse tasks on compromised devices, such as executing commands, managing processes, downloading additional payloads, manipulating Windows tokens, and executing shellcode. All of these operations are facilitated through a web-based management console, providing the attacker with visibility into compromised devices, events, and task outputs.
The source code for Havoc was uploaded to GitHub at the following URL:
https://github.com/HavocFramework/Havoc/blob/main/client/src/Havoc/Demon/ConsoleInput.cc#L876-L883.
The Havoc C2 framework, crafted by C5pider, consists of three primary components: the Demon agent, deployed on infected machines to communicate with a configured Teamserver; the Teamserver, functioning as the command and control (C2) server managing communications with agents; and the Client, utilized by threat actors to connect to a Teamserver for managing and issuing commands to connected agents.
In early January 2024, an undisclosed threat group deployed this post-exploitation kit as part of an attack campaign targeting a government organization. Observations by security experts revealed that the shellcode loader dropped on compromised systems disables the Event Tracing for Windows (ETW), and the final Havoc Demon payload is loaded without the DOS and NT headers to evade detection. Furthermore, the framework was distributed via a malicious npm package (Aabquerys), masquerading as a legitimate module, as reported by ReversingLabs’ research team earlier in the month. According to the report, “Demon.bin is a malicious agent with typical RAT (remote access trojan) functionalities that was generated using an open-source, post-exploitation, command and control framework named Havoc,” indicating its versatility in building malicious agents in various formats, including Windows PE executable, PE DLL, and shellcode.
Check Point Exposure Management is an intelligence-led, validation-driven, remediation-first unified platform that helps security teams move quickly and safely from exposure visibility to exposure reduction. Delivered through a single UI, it brings together threat intelligence, exposure prioritization, Agentic Exposure Validation, and safe remediation so teams can understand risk, prove exploitability, and act from one place.

| Tactic Name | Technique |
|---|---|
| Defense Evasion | T1562.001 – Disable or Modify Tools |
| Command and Control | T1573.001 – Symmetric Cryptography |
| Command and Control | T1071.001 – Web Protocols |
| Initial Access | T1195 – Supply Chain Compromise |
| Defense Evasion | T1036 – Masquerading |
| Privilege Escalation | T1547.001 – Registry Run Keys / Startup Folder |
| Persistence | T1547.001 – Registry Run Keys / Startup Folder |
| Command and Control | T1071 – Application Layer Protocol |
| Discovery | T1049 – System Network Connections Discovery |
| Discovery | T1016 – System Network Configuration Discovery |
| Discovery | T1057 – Process Discovery |
| Execution | T1059.003 – Windows Command Shell |
| Privilege Escalation | T1078 – Valid Accounts |
| Persistence | T1078 – Valid Accounts |
| Defense Evasion | T1078 – Valid Accounts |
| Initial Access | T1078 – Valid Accounts |
| Command and Control | T1105 – Ingress Tool Transfer |
| Privilege Escalation | T1574.002 – DLL Side-Loading |
| Persistence | T1574.002 – DLL Side-Loading |
| Defense Evasion | T1574.002 – DLL Side-Loading |
| Privilege Escalation | T1543.003 – Windows Service |
| Persistence | T1543.003 – Windows Service |
| Reconnaissance | T1590 – Gather Victim Network Information |
| Reconnaissance | T1592 – Gather Victim Host Information |
| Exfiltration | T1041 – Exfiltration Over C2 Channel |
| Defense Evasion | T1027.010 – Command Obfuscation |
| Command and Control | T1001 – Data Obfuscation |
| Defense Evasion | T1562 – Impair Defenses |
| Defense Evasion | T1628 – Hide Artifacts_x000D_&1#&9 [Confidential] |
| Type | Date Added | Value |
|---|---|---|
| IPv4 Address | 2026-08-02 | 168.144.89.89 |
| IPv4 Address | 2026-08-01 | 167.172.142.69 |
| IPv4 Address | 2026-07-31 | 144.172.93.33 |
| IPv4 Address | 2026-07-29 | 104.248.185.92 |
| IPv4 Address | 2026-07-28 | 91.92.40.96 |
| IPv4 Address | 2026-07-27 | 101.33.76.127 |
| IPv4 Address | 2026-07-27 | 70.34.215.48 |
| IPv4 Address | 2026-07-26 | 13.51.79.99 |
| IPv4 Address | 2026-07-25 | 151.236.21.109 |
| IPv4 Address | 2026-07-25 | 47.96.154.174 |
| IPv4 Address | 2026-07-24 | 200.234.219.26 |
| IPv4 Address | 2026-07-20 | 164.92.79.49 |
| IPv4 Address | 2026-07-18 | 161.35.239.147 |
| IPv4 Address | 2026-07-18 | 104.251.181.73 |
| IPv4 Address | 2026-07-18 | 161.35.176.231 |
| IPv4 Address | 2026-07-18 | 47.83.134.97 |
| IPv4 Address | 2026-07-18 | 46.225.160.243 |
| IPv4 Address | 2026-07-17 | 74.249.72.157 |
| IPv4 Address | 2026-07-15 | 47.251.241.59 |
| IPv4 Address | 2026-07-15 | 195.58.146.40 |
| IPv4 Address | 2026-07-14 | 172.86.119.141 |
| IPv4 Address | 2026-07-14 | 37.235.54.142 |
| IPv4 Address | 2026-07-12 | 66.97.33.99 |
| IPv4 Address | 2026-07-15 | 87.232.83.18 |
| IPv4 Address | 2026-07-10 | 123.215.57.178 |
| IPv4 Address | 2026-07-10 | 45.150.36.229 |
| IPv4 Address | 2026-07-10 | 212.46.38.117 |
| IPv4 Address | 2026-07-09 | 162.248.102.130 |
| IPv4 Address | 2026-07-08 | 8.133.197.201 |
| IPv4 Address | 2026-07-07 | 143.198.120.167 |
| IPv4 Address | 2026-07-07 | 173.249.41.141 |
| IPv4 Address | 2026-07-07 | 2.56.212.64 |
| IPv4 Address | 2026-07-06 | 77.105.169.126 |
| IPv4 Address | 2026-07-02 | 107.173.52.214 |
| IPv4 Address | 2026-07-02 | 192.236.148.154 |
| IPv4 Address | 2026-07-02 | 64.188.26.121 |
| IPv4 Address | 2026-07-02 | 192.210.226.224 |
| IPv4 Address | 2026-07-01 | 41.216.189.153 |
| IPv4 Address | 2026-07-01 | 107.172.22.3 |
| IPv4 Address | 2026-06-28 | 20.69.167.4 |
| IPv4 Address | 2026-06-28 | 101.245.74.162 |
| IPv4 Address | 2026-06-26 | 93.185.165.93 |
| IPv4 Address | 2026-06-25 | 185.115.161.32 |
| IPv4 Address | 2026-06-25 | 146.190.80.105 |
| IPv4 Address | 2026-06-23 | 150.40.117.39 |
| IPv4 Address | 2026-06-22 | 87.199.196.12 |
| IPv4 Address | 2026-06-20 | 139.180.190.68 |
| IPv4 Address | 2026-06-18 | 20.39.60.137 |
| IPv4 Address | 2026-06-17 | 177.104.165.104 |
| IPv4 Address | 2026-06-16 | 20.224.219.169_x000D_&1#&9 [Confidential] |
©1994–2026 Check Point Software Technologies Ltd. All rights reserved.
Copyright | Privacy Policy | Cookie Settings | Get the Latest News
Fill in your business email to start