Mythic
MITRE ATT&CK: S0699 View on attack.mitre.org
Aliases: Mythic
- First seen
- 2019-02-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows, linux, macos
- Related IoCs
- 7
- Last IoC activity
- 2026-05-07 05:17:28
- Profile updated
- 2026-07-07 14:48:26
Targeted industries: government-and-public-sector technology-and-telecommunications professional-services
Context
Mythic is an open source, cross-platform post-exploitation/command and control platform. Mythic is designed to "plug-n-play" with various agents and communication channels. Deployed Mythic C2 servers have been observed as part of potentially malicious infrastructure.
Detection coverage
- 1 YARA rules
- 85 Sigma rules
Malware & tools used
- External Proxy (attack-pattern)
- File Transfer Protocols (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- DNS (attack-pattern)
- Web Protocols (attack-pattern)
- Data Encoding (attack-pattern)
- Internal Proxy (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Data Transfer Size Limits (attack-pattern)
- Automated Collection (attack-pattern)
- Protocol Tunneling (attack-pattern)
- Domain Fronting (attack-pattern)
- Fallback Channels (attack-pattern)
Detection rules
- SIGNATURE_BASE_HKTL_NET_GUID_Mythic (yara-rule)
Reports & references
- go.recordedfuture.com — Cta 2022 0118 (report)
- MITRE ATT&CK — S0699 (report)
- docs.mythic-c2.net (report)
- github.com — Mythic (report)
- posts.specterops.io — A Change Of Mythic Proportions 21Debeb03617 (report)