Apollo and Mythic: A Myth Worth Retelling
ID: 52e0cf2b-f02c-5543-80a0-499ce55e0915
STIX ID: report--52e0cf2b-f02c-5543-80a0-499ce55e0915
Feed Name: SpecterOps Blog
This article presents a deep dive into Apollo, a Windows .NET agent for the Mythic C2 framework, showcasing operator-focused features such as browser-scripted task outputs, enhanced file and process triage (including ACLs and integrity levels), integrated screenshots and keylogging views, third-party .NET/PowerShell execution with on-the-fly injection technique selection, credential and token tracking, and comprehensive payload/artifact reporting. Emphasizing workflow, deconfliction, and OPSEC visibility, it demonstrates how Mythic’s UI and APIs enrich red-team operations and training without covering a specific incident or threat campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
