In early May 2025, security teams began noticing a sudden increase in the exploitation of an open-source command and control framework known as AdaptixC2.
See also: Vulnerabilities in open-source software are increasingly exploited

The framework, originally developed to aid penetration testers, offers a range of capabilities—file system manipulation, process enumeration, and covert channel traversal—that have now been adopted by malicious actors. The framework’s modular design and extensibility via “extenders” make it particularly attractive to attackers looking for a customizable tool that can evade traditional defenses.
Palo Alto Networks researchers noted that AdaptixC2 remained largely undetected until threat intelligence feeds began reporting infections across multiple domains. An early campaign relied on social engineering via fake remote support requests, tricking users into running Quick Assist sessions that unleashed a multi-stage PowerShell loader. Within minutes, the hackers achieved beacon memory execution without leaving any files, bypassing endpoint detection measures and installing persistent control on the victim’s computer
As the incidents multiplied, a different attack cluster emerged that included scripts generated by AI to deploy AdaptixC2. Palo Alto Networks analysts identified certain characteristics—numerical comments and extensive output assertions—that indicated code generated by large language models. These scripts not only downloaded and decrypted a Base64-encoded payload, but also used GetDelegateForFunctionPointer to execute shellcode directly in memory. By leveraging built-in Windows APIs like VirtualProtect and CreateProcess, the attackers achieved stealth deployment and reliable persistence.
See also: Brave's Cookiecrumbler tool becomes open-source

In all scenarios, the impact was significant. Compromised environments detected lateral traffic facilitated by SOCKS4/5 and port forwarding, allowing data to be extracted in small chunks to be combined with regular traffic patterns. In one documented case, hackers combined AdaptixC2 with Fog ransomware in an attack against a financial institution in Asia, demonstrating the framework’s flexibility and ability to amplify downstream payloads. Organizations relying on legacy detection systems found themselves unprepared for this modular, evolving threat.
One of the most insidious elements of AdaptixC2’s deployment is its fileless infection mechanism, which runs entirely in memory to evade disk-based defenses. The initial vector often starts with a seemingly innocent PowerShell, delivered via a social engineering email or remote support prompt. When executed, the script calls Invoke-RestMethod to retrieve a Base64-encoded shellcode payload from a legitimate cloud storage service. It then decodes this payload and calls VirtualAlloc to allocate a memory region with PAGE_EXECUTE_READWRITE. Using reflection and dynamic calling, the loader constructs a delegate that points to the shellcode entry point. This method bypasses the need for written executables, leaving minimal forensic traces. Upon successful execution, the script uses CreateShortcut in the user's Startup folder or writes a Run key to the registry with a well-known name such as "Updater", ensuring that the beacon survives reboots.
See also: CapibaraZero Firmware: New innovation in Open-Source technology

Detection avoidance is further enhanced by configurable KillDate and WorkingTime, which limit beacon activity to predefined windows, and by customizable user-agent strings and HTTP headers.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
