logo

Fake Tech Support Delivers Havoc Command & Control

ID: d9682842-b247-5529-b5e2-03505ff8dcb2

STIX ID: report--d9682842-b247-5529-b5e2-03505ff8dcb2

Feed Name: Huntress Blog

Threat Score
80/100

Date Published: 2026-03-02

Date Updated: 2026-04-28

...
...

This Huntress technical analysis documents a multi-organization intrusion campaign in February 2026 where attackers used spam and phone-based fake IT support to obtain remote access, then delivered a modified Havoc Demon C2 implant via DLL sideloading and fragmented payloads. The adversary employed advanced EDR-evasion (Hell's Gate/Halo's Gate indirect syscalls, Detours hooks, anti-emulation), diversified persistence (scheduled tasks, Level RMM, XEOX RMM), rapid lateral movement across nine endpoints, and registry-based fallback C2s; the report includes file and URL IOCs, timelines, and remediation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.