logo

Havoc Across the Cyberspace

ID: d0adbdb8-6340-5a0d-a92c-9b33314dbe6f

STIX ID: report--d0adbdb8-6340-5a0d-a92c-9b33314dbe6f

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report analyzes an in-the-wild campaign delivering the Havoc Demon post-exploitation implant: infection begins with a ZIP containing a BAT2EXE-compiled screensaver downloader that retrieves a signed shellcode loader (pics.exe) from http://146.190.48.229, which decrypts and executes a KaynLdr shellcode to reflectively map the Havoc DLL; the analysis documents ETW patching, API hashing, RWX allocation, AES-encrypted C2 communications, configuration values, available commands, and supporting IoCs and evasion techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.