Havoc
MITRE ATT&CK: S1229 View on attack.mitre.org
Aliases: HavocCrypt Ransomware, Havokiz, Havoc
- First seen
- 2022-10-01 00:00:00
- Malware type
- rat, backdoor, ransomware
- Family
- Malware family
- Operating systems
- linux, macos, windows
- Related IoCs
- 844 (426 malicious)
- Last IoC activity
- 2026-09-02 02:42:55
- Profile updated
- 2026-07-07 12:35:16
Targeted industries: government-and-public-sector technology-and-telecommunications financial-services
Context
Havoc is an open-source post-exploitation command and control (C2) framework first released on GitHub in October 2022 by C5pider (Paul Ungur), who continues to maintain and develop it with community contributors. Havoc provides a wide range of offensive security capabilities and has been adopted by multiple threat actors to establish and maintain control over compromised systems.
Recent IoC activity
429 malicious indicators in Maltiverse are attributed to Havoc (S1229). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| IP address | 149.28.153.80 | 2026-09-03 | 3 |
| hostname | vds2405267.my-ihor.ru | 2026-09-03 | 1 |
| hostname | duce.fascism.rocks | 2026-09-03 | 1 |
| hostname | vds2369972.my-ihor.ru | 2026-09-03 | 1 |
| hostname | login.sharepointoneline.com | 2026-09-03 | 1 |
| hostname | ec2-18-191-149-233.us-east-2.compute.amazonaws.com | 2026-09-03 | 1 |
| hostname | webmail.stockmrtktlite.xyz | 2026-09-03 | 1 |
| hostname | 211.20.97.83.ro.ovo.sc | 2026-09-03 | 1 |
| hostname | linkair.top | 2026-09-03 | 1 |
| hostname | vigorous-raman.82-223-64-37.plesk.page | 2026-09-03 | 1 |
| hostname | msoffice360.com | 2026-09-03 | 1 |
| hostname | img6.mllcrosoft.com | 2026-09-03 | 1 |
| hostname | 23-227-193-214.static.hvvc.us | 2026-09-03 | 1 |
| hostname | vpn366710782.softether.net | 2026-09-03 | 1 |
| hostname | cpcontacts.sports777games.com | 2026-09-03 | 1 |
| hostname | webmail.topdigihub.com | 2026-09-03 | 1 |
| hostname | testexternal.mettlab.online | 2026-09-03 | 1 |
| hostname | libereco.xyz | 2026-09-03 | 1 |
| hostname | webdisk.dmfortsites.xyz | 2026-09-03 | 1 |
| hostname | 54.176.169.192.host.secureserver.net | 2026-09-03 | 1 |
Detection coverage
- 4 YARA rules
- 631 Sigma rules
Malware & tools used
- System Owner/User Discovery (attack-pattern)
- Proxy (attack-pattern)
- Inter-Process Communication (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Malicious Copy and Paste (attack-pattern)
- Windows Command Shell (attack-pattern)
- Screen Capture (attack-pattern)
- Token Impersonation/Theft (attack-pattern)
- Web Protocols (attack-pattern)
- System Information Discovery (attack-pattern)
- Process Discovery (attack-pattern)
- PowerShell (attack-pattern)
- Portable Executable Injection (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- File and Directory Discovery (attack-pattern)
- DLL (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
- Internet Connection Discovery (attack-pattern)
- Account Discovery (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Command Obfuscation (attack-pattern)
- Time Based Checks (attack-pattern)
- File Transfer Protocols (attack-pattern)
- Data from Local System (attack-pattern)
- Malicious File (attack-pattern)
Used by threat actors
- WIRTE (threat-actor)
- SloppyLemming (threat-actor)
- MacroPack Payload Delivery Activity (campaign)
Detection rules
- EMBEERESEARCH_Win_Havoc_Djb2_Hashing_Routine_Oct_2022 (yara-rule)
- DITEKSHEN_INDICATOR_TOOL_Havoc (yara-rule)
- SEKOIA_Implant_Win_Havoc_Default_Strings (yara-rule)
- MALPEDIA_Win_Havoc_Auto (yara-rule)
Reports & references
- Broadcom/Symantec — Grayling Taiwan Cyber Attacks (report)
- id-ransomware.blogspot.co.il — Havoc Ransomware (report)
- spamhaus.org — Botnet Threat Update January To June 2025 (report)
- info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
- spamhaus.org — Botnet Threat Update July To December 2025 (report)
- info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q3%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — Q4%202023%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q2%20Botnet%20Threat%20Update (report)
- threatray.com — The Bitter End Unraveling Eight Years Of Espionage Antics Part Two (report)
- proofpoint.com — Bitter End Unraveling Eight Years Espionage Antics Part One (report)
- jsac.jpcert.or.jp — Jsac2024 1 9 Takeda Furukawa En (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Havoc (report)
- fortinet.com — Fortiguard Incident Response Team Detects Intrusion Into Middle East Critical National Infrastructure (report)
- youtube.com — Watch (report)
- 4pfsec.com — Havoc C2 First Look (report)
- seqrite.com — Operation Oxidovy Sophisticated Malware Campaign Targets Czech Officials Using Nato Themed Decoys (report)
- twitter.com — 1579668721777643520 (report)
- kroll.com — Prelude Crypto Heist Causes Havoc (report)
- checkmarx.com — First Known Targeted Oss Supply Chain Attacks Against The Banking Sector (report)
- github.com — Havoc (report)
- zscaler.com — Havoc Across Cyberspace (report)
- immersivelabs.com — Havoc C2 Framework A Defensive Operators Guide (report)
- github.com — Parse Havoc Generic.Py (report)
- fortinet.com — Report Incident Response Middle East (report)