Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Havoc

69
Global rank
73 infographic chevron month
Month rank
59
Week rank

Havoc is an advanced post-exploitation framework used by hackers to take control of a system once they've breached it. With Havoc, attackers can run commands remotely, inject malicious processes, and access sensitive data. It's often used in targeted attacks, allowing cybercriminals to stay hidden in a network while stealing information or launching further attacks. Its flexibility and ability to bypass detection make it a serious threat, especially in environments that rely on traditional security tools.

C2 Framework
Type
Unknown
Origin
1 October, 2022
First seen
4 October, 2026
Last seen

How to analyze Havoc with ANY.RUN

C2 Framework
Type
Unknown
Origin
1 October, 2022
First seen
4 October, 2026
Last seen

IOCs

IP addresses
23.222.81.129
121.26.23.21
193.178.158.57
89.208.104.175
205.185.113.69
155.102.51.14
21.182.234.235
62.78.182.43
130.185.158.231
33.17.76.22
43.2.33.196
210.162.116.45
61.111.141.0
210.162.132.109
210.222.59.225
203.202.232.203
67.164.165.240
21.235.175.251
101.47.31.104
86.36.236.238
Hashes
efbdbbcd0d954f8fdc53467de5d89ad525e4e4a9cfff8a15d07c6fdb350c407f
92804faaab2175dc501d73e814663058c78c0a042675a8937266357bcfb96c50
6823b98c3e922490a2f97f54862d32193900077e49f0360522b19e06e6da24b4
d96856cd944a9f1587907cacef974c0248b7f4210f1689c1e6bcac5fed289368
1a087dddaed584b9df580672ff112d538b02a3005862ba2a38147c498a5f4c01
e728f79439e07df1afbcf03e8788fa0b8b08cf459db31fc8568bc511bf799537
7f0121322785c107bfdfe343e49f06c604c719baff849d07b6e099675d173961
aac73b3148f6d1d7111dbca32099f68d26c644c6813ae1e4f05f6579aa2663fe
72f6b34d3c8f424ff0a290a793fcfbf34fd5630a916cd02e0a5dda0144b5957f
62866e95501c436b329a15432355743c6efd64a37cfb65bcece465ab63ecf240
462a8ff8fd051a8100e8c6c086f497e4056ace5b20b44791f4aab964b010a448
5fc25c30aee76477f1c4e922931cc806823df059525583ff5705705d9e913c1c
e538f8f4934ca6e1ce29416d292171f28e67da6c72ed9d236ba42f37445ea41e
46079c0a1b660fc187aafd760707f369d0b60d424d878c57685545a3fce95819
2eb96422375f1a7b687115b132a4005d2e7d3d5dc091fb0eb22a6471e712848e
b7ee468f5b6c650dada7db3ad9e115a0e97135b3df095c3220dfd22ba277b607
629e52ba4e2dca91b10ef7729a1722888e01284eed7dda6030d0a1ec46c94086
76d8e4ed946deefeefa0d0012c276f0b61f3d1c84af00533f4931546cbb2f99e
5c9bc70586ad538b0df1fcf5d6f1f3527450ae16935aa34bd7eb494b4f1b2db9
72c639d1afda32a65143bcbe016fe5d8b46d17924f5f5190eb04efe954c1199a
Domains
dlipabqpglrj.net
vuelaviajero.com
forsell.tech
cryptovectorhub3.lol
wittenhorst.eu
pvwvaxkcvuah.org
syymkqeftivx.co.uk
qbaevriiwclb.co.uk
raw.githubusercontent.com
noithaticon.vn
defenddsouneuw.shop
turing.captcha.qcloud.com
ihekyvvxspvca.biz
steamcommunity.com
covvercilverow.shop
client.wns.windows.com
xn--h6qpop2cq9nl9c.pages.dev
ip-api.com
87130921-60-20220830152356.webstarterz.com
ryanmorales.me
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://192.162.199.246/pb7ulzhaae3xpsnrevjh5yqqymyibnnf/mkm65cf6qnqeovw9.exe
http://192.162.199.149/uploads/0c83aee7a8ad48ecb075c59c5b4957f3.exe
http://196.251.107.186/1.exe
http://178.16.54.109/spm.exe
http://185.213.240.64/bot.exe
http://192.162.199.149/uploads/f3eeb7dfc18246f7bc40a5704a81d193.exe
http://91.92.242.236/files-129312398/files/file_73ed34a7752ecb3a.exe
http://193.178.158.57/bin/bc116af5e724cfa4_zx.exe
http://31.56.209.11/svc.exe
http://64.89.163.22/8.exe
http://193.178.158.57/bin/67dbf1a8e19934e4_thread_hijacking_cayoy4nb.exe
http://151.242.30.165/s.ps1
http://64.89.161.131/bin/screenconnect.clientsetup.exe
http://193.178.158.57/bin/e6efd8bd3bf0fae2_moratorium_0.96.2.9_install.exe
http://45.135.194.95/bin/support.client.exe
http://45.135.194.95/bin/screenconnect.clientsetup.exe
http://196.251.121.178/bin/screenconnect.clientsetup.exe
Last Seen at
Last Seen at

Recent blog posts

post image
5 Critical Pain Points of Modern US SOCs and...
watchers 1128
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 2922
comments 0
post image
Threat Coverage Digest: New Malware Reports a...
watchers 10390
comments 0

What is Havoc malware?

Havoc is a post-exploitation framework used by cybercriminals and penetration testers to perform a variety of attacks and gain deeper control over compromised systems. It is developed by C5pider, written in Golang, C++, and C.

First observed in 2022, it has become notable for its stealth, flexibility, and use of encrypted communications to avoid detection. The malware is used in advanced campaigns, often by threat actors conducting highly targeted attacks.

It has been linked to attacks targeting corporate networks, critical infrastructure, and government entities.

Key technical details include its ability to use reflective DLL injection and direct memory manipulation to execute payloads. It maintains persistence on compromised systems through registry modifications and scheduled tasks, while its communication with command-and-control (C2) servers is highly encrypted

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Havoc malware technical details

Havoc malware has several powerful and dangerous capabilities, making it a significant post-exploitation tool. Some of its primary technical features include:

  • Uses reflective DLL injection to inject its payloads directly into the memory of a process without writing to disk, minimizing the risk of detection.
  • Can perform direct memory manipulation to execute malicious code.
  • Supports multiple communication channels (HTTP/HTTPS, DNS, SMB), all encrypted using TLS, making it difficult to intercept and analyze its traffic.
  • Includes a shellcode loader, capable of disabling Event Tracing for Windows (ETW) and performing system reconnaissance.
  • Can establish persistence using methods such as registry modifications, scheduled tasks, and service creation.
  • Allows operators to upload, download, and manipulate files remotely, which is a key post-exploitation feature for attackers.

Havoc operates primarily as an open-source framework and is typically distributed through phishing campaigns or malicious downloads. Its advanced features include payload generation, encryption (using algorithms like AES and RSA), process injection techniques, and multiple communication channels (HTTP, HTTPS, DNS, and SMB).

Havoc malware execution process

To see how Havoc operates, let’s upload a Havoc sample to the ANY.RUN sandbox.

After executing the sample in the sandbox, the first thing that stands out is the red label in the upper right corner of the screen. This label provides a quick way to determine whether the activity is malicious. In our case, it’s highlighted in red, confirming that the behavior is indeed malicious.

Havoc in ANY.RUN sandbox Analysis of Havoc in the ANY.RUN sandbox

The ANY.RUN sandbox provides a Suricata rule flagging Havoc’s suspicious network activity, which is further evidence of its malicious behavior.

Havoc Suricatain ANY.RUN Malicious network activity detected by Suricata IDS in the ANY.RUN sandbox

The Havoc framework establishes a Command and Control (C2) channel using encrypted protocols such as HTTPS and SMB to evade detection. Its modular architecture allows for functionalities like privilege escalation, lateral movement, and data exfiltration. The core agent, "Demon," written in C and Assembly, uses techniques like indirect syscalls for Nt* APIs, x64 return address spoofing, and sleep obfuscation to bypass defenses.

Havoc offers capabilities such as:

  • Stagers: Lightweight payloads that establish a foothold.
  • Shellcode injectors: Inject shellcode into remote processes, allowing execution without disk traces.
  • Reflective DLL loaders: Bypass traditional antivirus by loading DLLs directly into memory.
  • Custom plugins: Support for credential harvesting, keylogging, and system information gathering.

It supports execution with Beacon Object Files (BOFs), enabling direct memory interaction, and can execute commands using cmd.exe and powershell.exe and is capable of deploying additional payloads to infected systems. Havoc employs advanced evasion techniques, such as process injection and anti-VM/sandbox checks.

For persistence, Havoc can modify system settings, create scheduled tasks, or alter startup configurations, ensuring continued control over compromised systems.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Havoc malware distribution methods

Havoc malware is distributed through a variety of methods that are commonly seen in advanced cyber threats:

  • Phishing emails: Havoc can be delivered via phishing campaigns, where malicious attachments or links are included in seemingly legitimate emails. These attachments often contain malicious macros or scripts that launch the malware once opened by the victim.
  • Malicious downloads: Attackers may trick users into downloading Havoc through fake software updates, cracked software, or malicious files hosted on compromised websites. These files may appear harmless but execute the malware when run.
  • Exploitation of vulnerabilities: Havoc can be deployed by exploiting known software vulnerabilities in operating systems or third-party applications, allowing attackers to gain access to systems remotely.
  • Malvertising: Havoc could be spread via malicious advertisements that redirect users to compromised or malicious websites where the malware is downloaded.

Gathering Threat Intelligence on Havoc Malware

To collect the latest intelligence on Havoc malware, utilize Threat Intelligence Lookup.

This service allows you to access a vast database with insights from millions of malware analysis sessions in the ANY.RUN sandbox. You can customize your search using over 40 different parameters, such as IP addresses, file names, command line artifacts, and process indicators, to find relevant details on Havoc and its behavior.

Havoc in TI Lookup ANY.RUN Search results for Havoc in Threat Intelligence Lookup

For example, by searching for Havoc's threat name (threatName:"Havoc"), you can uncover related samples and sandbox analysis results. This helps security professionals stay up to date on malware's evolution and techniques.

Start exploring these capabilities with a 14-day free trial of Threat Intelligence Lookup, alongside the ANY.RUN sandbox for deep, real-time analysis.

Conclusion

Havoc poses a significant threat due to its advanced evasion techniques, process manipulation, and ability to execute malicious payloads, making it highly dangerous for businesses. To protect against such threats, it’s important to carry out proactive malware analysis of suspicious files and URLs.

ANY.RUN provides real-time threat detection, allowing users to explore malware behavior, gather detailed reports on malware, such as Havoc.

Sign up for a free ANY.RUN account today and start analyzing threats in real-time!

HAVE A LOOK AT

Stealer screenshot
Stealer
stealer
Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.
Read More
DoubleTrouble screenshot
DoubleTrouble
doubletrouble
DoubleTrouble is a new-generation Android malware designed to quietly infiltrate mobile devices, harvest sensitive data, hijack financial operations, and maintain long-term persistence. Unlike commodity Android trojans, it blends advanced evasion, dual-stage infection, and dynamic payload updates, making it a rising mobile threat for both consumers and organizations.
Read More
Spynote screenshot
Spynote
spynote
SpyNote, also known as SpyMax and CypherRat, is a powerful Android malware family designed primarily for surveillance and data theft, often categorized as a Remote Access Trojan (RAT). Originally emerged in 2016, SpyNote has evolved significantly, with new variants continuing to appear as recently as 2023–2025.
Read More
Miolab Stealer screenshot
Miolab Stealer is a macOS malware threat designed to steal user credentials and sensitive files without raising immediate suspicion. It relies on fake system prompts and legitimate built-in tools to make malicious actions look routine. Instead of causing obvious disruption, it quietly collects valuable data and prepares it for exfiltration from the device. By blending deception with trusted macOS behavior, it increases the chance that the attack will go unnoticed in its early stages. This makes early behavioral detection critical before the theft of credentials and files is complete.
Read More
FatalRAT screenshot
FatalRAT
fatalrat
FatalRAT is a malware that gives hackers remote access and control of the system and lets them steal sensitive information like login credentials and financial data. FatalRAT has been associated with cyber espionage campaigns, particularly targeting organizations in the Asia-Pacific (APAC) region.
Read More
GREENBLOOD screenshot
GREENBLOOD
greenblood
GREENBLOOD is a Go-based ransomware that uses concurrent ChaCha8 encryption to lock entire Windows environments in under a minute while systematically destroying backups, disabling defenses, and threatening double extortion through a Tor-based data leak site.
Read More