HomeSecurityHackers use Havoc as an alternative to Cobalt Strike

Hackers use Havoc as an alternative to Cobalt Strike

Cybersecurity experts have spotted malicious actors shifting to an open-source C2 platform called Havoc as a substitute for paid alternatives like Cobalt Strike and Brute Ratel.

Havoc is an extremely versatile tool, offering cross-platform compatibility and the ability to bypass Microsoft Defender on Windows 11 devices with its unique sleep obfuscation feature, return address spoofing technique, and indirect syscalls.

Like other exploit kits, Havoc includes a wide variety of modules that allow pen testers (and hackers) to perform various tasks on exploited devices, such as executing commands, managing processes, downloading additional payloads, manipulating Windows tokens, and executing shellcode.

With the web-based management console, attackers can easily monitor their compromised devices, view events and task output.

See also: RedEyes: Uses M2RAT malware to steal data from Windows and phones

Havoc

Havoc was abused in attacks

During an attack campaign in early January, a mysterious group released this exploit kit after exploiting it to target and exploit an undisclosed government organization .

As observed by the Zscaler ThreatLabz research team that discovered it, the shellcode loader dropped on compromised systems will disable Event Tracing for Windows (ETW) and the final Havoc Demon payload is loaded without the DOS and NT headers to avoid detection.

The framework was also deployed via a malicious npm package (Aabquerys) that impersonates the legitimate module, as revealed in a report by the ReversingLabs research team earlier this month.

See also: Hyundai and Kia release patch for dangerous security flaw

Cobalt Strike

More Cobalt Strike alternatives are being developed

While Cobalt Strike has become the most common tool used by various threat actors to drop “beacons” into their victims’ compromised networks for later movement and delivery of additional malicious payloads, some of them have also recently begun to look for alternatives as defenders have become better at detecting and stopping their attacks .

As BleepingComputer previously reported, other alternatives include Brute Ratel and Sliver.

A variety of malicious threat groups, from financially motivated cybercrime gangs to state-backed hacking units, have already tested these two C2 frameworks in the field.

See also: Windows 11: Fixes one of the most annoying bugs

Brute Ratel, a post-exploitation toolkit developed by former Mandiant and CrowdStrike partner Chetan Nayak, has been used in attacks suspected of being linked to the Russian- sponsored APT29 (aka CozyBear ) hacking group . At the same time, some Brute Ratel licenses have likely landed in the hands of former members of the Conti ransomware gang .

In August 2022, Microsoft warned that several malicious actors, such as state-backed groups and cybercrime gangs ( APT29 , FIN12, Bumblebee/Coldtrain), are using the Go -based Sliver C2 framework created by researchers at BishopFox.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS