PULSE NAME
Fake Tech Support Delivers Havoc Command & Control
WHITE AlienVault 2026-03-05 Modified: 2026-03-06
15
IOCs
MEDIUM VOLUME
A sophisticated cyber attack campaign combines social engineering and advanced malware techniques. Attackers pose as IT support to gain initial access, then deploy a modified version of the Havoc C2 framework. The malware uses DLL sideloading, indirect syscalls, and custom loaders to evade detection. After compromising the initial system, the attackers rapidly move laterally, establishing persistence through scheduled tasks and legitimate remote monitoring tools. The campaign demonstrates a blend of human-centric initial access methods and advanced technical evasion techniques, highlighting the need for comprehensive security measures spanning user awareness and technical controls.
Indicators of Compromise (15)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 3e6cd9a31719d1cce2083299c8f44ae1 2026-03-05
FileHash-SHA1 b69078cb5a44132271dabd01e1cb77606e399884 2026-03-05
FileHash-SHA256 0dce1175dc50d20da0fc009d0eed30fb75a004389fca0fbe0abe9835631d745c 2026-03-05
FileHash-SHA256 1175b1c56d59b736fe25495674ee3f83848e7785fde8ba9e207d283fed9b36c7 2026-03-05
FileHash-SHA256 59014e97287b5602bba192a04535c59c60c6eb3a9770a94293551dfd5390c5c2 2026-03-05
FileHash-SHA256 6fbd98bbdb8a34dd563f29f45c66adf5c53b1aff225269af3ceb56d76ecd677d 2026-03-05
FileHash-SHA256 96c3b7ec47ca5ffaac5da1fda25b1ad1afa91e57e1586165deec1e541f3def2e 2026-03-05
FileHash-SHA256 b1ccee3d0dc7a85c117580cc08b8edcb8118b5612669300d4b006f50663b387e 2026-03-05
FileHash-SHA256 d96d8b01d034ca1b9b232c70d57a863320cc107e07245ef7308cbdb069031e61 2026-03-05
domain afzarkara.com 2026-03-05
domain agricularly.com 2026-03-05
domain alatastro.com 2026-03-05
domain arcupondepago.com 2026-03-05
domain bongsebing.com 2026-03-05
domain egravy.com 2026-03-05