logo

Apollo and Mythic: A Myth Worth Retelling

ID: 52e0cf2b-f02c-5543-80a0-499ce55e0915

STIX ID: report--52e0cf2b-f02c-5543-80a0-499ce55e0915

Feed Name: SpecterOps Blog

Date Published: 2020-11-12

Date Updated: 2026-04-30

Author: Dwight Hohnstein

...
...

This article presents a deep dive into Apollo, a Windows .NET agent for the Mythic C2 framework, showcasing operator-focused features such as browser-scripted task outputs, enhanced file and process triage (including ACLs and integrity levels), integrated screenshots and keylogging views, third-party .NET/PowerShell execution with on-the-fly injection technique selection, credential and token tracking, and comprehensive payload/artifact reporting. Emphasizing workflow, deconfliction, and OPSEC visibility, it demonstrates how Mythic’s UI and APIs enrich red-team operations and training without covering a specific incident or threat campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.