Malware.View on attack.mitre.org
Havoc is an open-source post-exploitation command and control (C2) framework first released on GitHub in October 2022 by C5pider (Paul Ungur), who continues to maintain and develop it with community contributors. Havoc provides a wide range of offensive security capabilities and has been adopted by multiple threat actors to establish and maintain control over compromised systems.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Havoc can download files from the victim's computer. |
| T1016 System Network Configuration Discovery |
Havoc has a module for network enumeration including determining IP addresses. |
| T1016.001 Internet Connection Discovery |
The Havoc demon can check for a connection to the C2 server from the target machine. |
| T1018 Remote System Discovery |
Havoc features a module capable of host enumeration. |
| T1027.010 Command Obfuscation |
Havoc has utilized XOR encryption with the key “01-01-1900” to obfuscate command strings. |
| T1033 System Owner/User Discovery |
Havoc can trigger exection of `whoami` on the target host to display the current user. |
| T1055.001 Dynamic-link Library Injection |
Havoc has DLL spawn and injection modules. |
| T1055.002 Portable Executable Injection |
Havoc has itself injected into `C:\\Windows\\System32\\Werfault.exe` on targeted systems. |
| T1057 Process Discovery |
Havoc can enumerate processes on targeted hosts. |
| T1059.001 PowerShell |
Havoc can facilitate the execution of PowerShell commands. |
| T1059.003 Windows Command Shell |
Havoc can execute commands via `cmd.exe`. |
| T1071.001 Web Protocols |
Havoc can use HTTP/S listeners to establish and maintain C2 communications. |
| T1071.002 File Transfer Protocols |
Havoc can use an SMB listener for C2 communication. |
| T1082 System Information Discovery |
Havoc can gather system information including hostname, domain, and OS details. |
| T1083 File and Directory Discovery |
The Havoc interface can display a file explorer view of the compromised host. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.