PULSE NAME
AdaptixC2: A New Open-Source Framework Leveraged in Real-World Attacks
WHITE AlienVault 2025-09-10 Modified: 2025-09-10
31
IOCs
MEDIUM VOLUME
AdaptixC2, an open-source post-exploitation and adversarial emulation framework, has been observed being used in real-world attacks. This versatile tool allows threat actors to execute commands, transfer files, and perform data exfiltration on compromised systems. Its open-source nature enables easy customization, making it highly flexible and dangerous. The framework supports sophisticated tunneling capabilities, modular design with extenders, and various beacon agent formats. Two infection scenarios were analyzed: one using social engineering via Microsoft Teams, and another likely involving AI-generated scripts. The increasing prevalence of AdaptixC2 in attacks, including its use alongside ransomware, highlights the growing trend of attackers leveraging customizable frameworks to evade detection.
Indicators of Compromise (31)
All FileHash-SHA1 FileHash-SHA256 YARA domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 a7401fa3fdbc7ae6b632c40570292f844e40ff40 2025-09-10
FileHash-SHA256 19c174f74b9de744502cdf47512ff10bba58248aa79a872ad64c23398e19580b 2025-09-10
FileHash-SHA256 750b29ca6d52a55d0ba8f13e297244ee8d1b96066a9944f4aac88598ae000f41 2025-09-10
FileHash-SHA256 83ac38fb389a56a6bd5eb39abf2ad81fab84a7382da296a855f62f3cdd9d629d 2025-09-10
FileHash-SHA256 ad96a3dab7f201dd7c9938dcf70d6921849f92c1a20a84a28b28d11f40f0fb06 2025-09-10
FileHash-SHA256 b81aa37867f0ec772951ac30a5616db4d23ea49f7fd1a07bb1f1f45e304fc625 2025-09-10
FileHash-SHA256 bdb1b9e37f6467b5f98d151a43f280f319bacf18198b22f55722292a832933ab 2025-09-10
FileHash-SHA256 df0d4ba2e0799f337daac2b0ad7a64d80b7bcd68b7b57d2a26e47b2f520cc260 2025-09-10
YARA 3c3e7e67d31f3ec7f9aa5c542482fd855c3b1d36 2025-09-10
YARA 78d47f5c63882c341b29ea2f83beafdcdef2adb0 2025-09-10
YARA 9682ea925ee919ef51d65409465f2eb53ac60c28 2025-09-10
domain buenohuy.live 2025-09-10
domain doamin.cc 2025-09-10
domain express1solutions.com 2025-09-10
domain firetrue.live 2025-09-10
domain iorestore.com 2025-09-10
domain lokipoki.live 2025-09-10
domain mautau.live 2025-09-10
domain moldostonesupplies.pro 2025-09-10
domain muatay.live 2025-09-10
domain nicepliced.live 2025-09-10
domain nissi.bg 2025-09-10
domain novelumbsasa.art 2025-09-10
domain picasosoftai.shop 2025-09-10
domain protoflint.com 2025-09-10
domain regonalone.com 2025-09-10
domain self.data 2025-09-10
domain tech-system.online 2025-09-10
domain veryspec.live 2025-09-10
domain x6iye.site 2025-09-10
hostname dtt.alux.cc 2025-09-10