logo

Fake Tech Support Spam Deploys Customized Havoc C2 Across Organizations

ID: 0a861c1a-d786-5ac0-a70d-fa9128ffde2c

STIX ID: report--0a861c1a-d786-5ac0-a70d-fa9128ffde2c

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-03-03

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Threat actors ran a multi-stage campaign impersonating IT support (email lures + phone calls) to obtain remote access, harvest credentials with a fake Microsoft page, and sideload malicious DLLs (e.g., vcruntime140_1.dll) via legitimate binaries (ADNotificationManager.exe, DLPUserAgent.exe, Werfault.exe) to deploy the Havoc Demon C2. They combined DLL sideloading, EDR bypass techniques and legitimate RMM tools for persistence and achieved rapid lateral movement—moving to nine additional endpoints in eleven hours—indicating likely data exfiltration or ransomware objectives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.