logo

Havoc: SharePoint with Microsoft Graph API turns into FUD C2

ID: 10ad5527-43ad-5089-b636-679b75dbb426

STIX ID: report--10ad5527-43ad-5089-b636-679b75dbb426

Feed Name: Fortinet Blog

Threat Score
78/100

Date Published: 2025-03-03

Date Updated: 2026-04-27

...
...

FortiGuard Labs details a high-severity phishing campaign that uses a ClickFix HTML lure and multi-stage loaders (PowerShell -> Python shellcode loader -> KaynLdr) to deploy a modified Havoc Demon backdoor; the Havoc agent is altered to use Microsoft Graph API and SharePoint files for covert C2 communications, and the report includes technical analysis, mitigations, Fortinet detections, and IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.