AdaptixC2: A New Open-Source Framework Leveraged in Real-World Attacks
Essential information
- Published
- 10/09/2025 16:37
- Modified
- 10/09/2025 20:11
- Tags
- 2025-09-10 adaptixc2 adversarial emulation ai-generated scripts c2 framework data exfiltration foggyweb open-source post-exploitation social engineering tunneling
- Related entities
- 18 techniques (mitre), 1 others
Description
AdaptixC2, an open-source post-exploitation and adversarial emulation framework, has been observed being used in real-world attacks. This versatile tool allows threat actors to execute commands, transfer files, and perform data exfiltration on compromised systems. Its open-source nature enables easy customization, making it highly flexible and dangerous. The framework supports sophisticated tunneling capabilities, modular design with extenders, and various beacon agent formats. Two infection scenarios were analyzed: one using social engineering via Microsoft Teams, and another likely involving AI-generated scripts. The increasing prevalence of AdaptixC2 in attacks, including its use alongside ransomware, highlights the growing trend of attackers leveraging customizable frameworks to evade detection.