216.73.216.226

Havoc: SharePoint with Microsoft Graph API turns into FUD C2

· Published 03/03/2025 18:02 · Modified 04/03/2025 09:34

Export JSON

Essential information

Published
03/03/2025 18:02
Modified
04/03/2025 09:34
Tags
2025-03-03 c2 framework clickfix havoc havoc demon agent kaynldr multi-stage malware phishing sharepoint
Related entities
5 observables, 18 techniques (mitre), 2 malware

Description

A campaign combines and to deploy a modified . The attack starts with an HTML attachment using to deceive users into executing malicious PowerShell commands. The malware stages are hidden behind sites, and a modified Demon uses Microsoft Graph API to obscure C2 communications. The attack chain includes sandbox evasion, Python shellcode loader, for DLL loading, and a customized Demon DLL. The threat actor creates two files in for C2 communication, encrypts data with AES-256, and supports various malicious commands. This campaign demonstrates the integration of public services with modified open-source tools to evade detection.

External references