Fake Tech Support Spam Deploys Customized Havoc C2 Across Organizations
ID: 0a861c1a-d786-5ac0-a70d-fa9128ffde2c
STIX ID: report--0a861c1a-d786-5ac0-a70d-fa9128ffde2c
Feed Name: The Hacker News
Threat actors ran a multi-stage campaign impersonating IT support (email lures + phone calls) to obtain remote access, harvest credentials with a fake Microsoft page, and sideload malicious DLLs (e.g., vcruntime140_1.dll) via legitimate binaries (ADNotificationManager.exe, DLPUserAgent.exe, Werfault.exe) to deploy the Havoc Demon C2. They combined DLL sideloading, EDR bypass techniques and legitimate RMM tools for persistence and achieved rapid lateral movement—moving to nine additional endpoints in eleven hours—indicating likely data exfiltration or ransomware objectives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
