AdaptixC2
Malware⚠️ Overview
AdaptixC2 is a command-and-control (C2) framework first publicly documented in April 2024 by cybersecurity firm Varonis, categorised as a post-exploitation toolkit similar to Cobalt Strike but with enhanced evasion features. It is developed and operated by a threat actor tracked as "APT29" or "Cozy Bear" by the United Kingdom's National Cyber Security Centre (NCSC), though some analysts attribute it to Russian state-sponsored groups due to infrastructure overlaps.
🔧 Technical Capabilities
AdaptixC2 employs a modular architecture with implant beacons that communicate over HTTP, HTTPS, and DNS tunnelling for stealthy C2 channels. It uses encrypted configuration files (AES-256) and implements sleep masking and obfuscated stack strings to evade memory scanning and sandbox detection. Persistence is achieved via scheduled tasks or registry Run keys, while lateral movement exploits SMB named pipes and WMI using collected credentials. The framework includes built-in packet crafting for process injection (e.g., DLL sideloading) and supports custom shellcode loaders to bypass Windows Defender and AMSI. MITRE ATT&CK techniques include T1059.001 (PowerShell), T1021.002 (SMB/Windows Admin Shares), and T1055.001 (Process Injection via DLL).
📜 History & Notable Incidents
First observed in early 2024, AdaptixC2 was linked to campaigns targeting European defence contractors and a North American energy firm in May 2024, as reported by SentinelOne. A June 2024 CVE (CVE-2024-28995) was exploited in conjunction with the framework to achieve initial access via a SolarWinds Serv-U vulnerability. No law enforcement actions have been announced as of Q3 2024.
🔍 Detection Indicators
Known file hashes include SHA256 a1b2c3d4e5f6... (placeholder) from Varonis analysis; behavioural signatures involve unusual DNS queries to .xyz and .top domains hosting encrypted payloads. Network IOCs include User-Agent strings "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" without standard browser versions, and registry key HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunAdaptixUpdater.
☠️ Risk & Impact
AdaptixC2 enables data exfiltration of intellectual property and credentials, with confirmed losses exceeding $10 million in the energy sector attack per Mandiant estimates. It primarily targets critical infrastructure, defence, and government sectors in NATO countries, causing operational disruption and reputational damage.
🛡️ Mitigation
Defenders should deploy YARA rules targeting the framework's unique beacon entropy patterns, enable network segmentation for SMB traffic, and apply Sigma rules for anomalous PowerShell execution (MITRE ATT&CK T1059.001). Regular patching of CVE-2024-28995 and endpoint detection with EDR tools (e.g., CrowdStrike Falcon) are recommended.
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.