216.73.217.22

Fake Tech Support Delivers Havoc Command & Control

· Published 05/03/2026 12:32 · Modified 05/03/2026 15:20

Export JSON

Essential information

Published
05/03/2026 12:32
Modified
05/03/2026 15:20
Tags
2026-03-05 dll sideloading evasion techniques havoc havoc c2 havoc demon lateral movement remote monitoring tools social engineering syscalls
Related entities
11 observables, 1 techniques (mitre), 2 malware, 6 others

Description

A sophisticated cyber attack campaign combines and advanced malware techniques. Attackers pose as IT support to gain initial access, then deploy a modified version of the framework. The malware uses , indirect , and custom loaders to evade detection. After compromising the initial system, the attackers rapidly move laterally, establishing persistence through scheduled tasks and legitimate . The campaign demonstrates a blend of human-centric initial access methods and advanced technical , highlighting the need for comprehensive security measures spanning user awareness and technical controls.

External references