A recently identified campaign uses fake IT support to deliver a customized Havoc command-and-control (C2) framework across multiple organizations. This sophisticated attack, discovered by Huntress, often serves as a precursor to data exfiltration or ransomware.
The Attack Chain
The multi-stage intrusion leverages high-pressure social engineering and advanced technical evasion:
- Initial Lure: Threat actors inundate targets with email spam to overwhelm them.
- Social Engineering: Posing as IT help desk staff, attackers call the user to offer “remediation” for the spam.
- Gaining Access: Users are persuaded to grant remote access via tools like Quick Assist or AnyDesk.
- Malware Delivery: Once in, attackers deploy a layered pipeline that includes:
- Custom Havoc Demon Payloads: These agents are modified to bypass traditional security.
- Evasion Techniques: The malware uses DLL side-loading, HellsGate/Halos Gate for syscall evasion, and registry-based C2.
- Persistence & Lateral Movement: Attackers often install legitimate Remote Monitoring and Management (RMM) tools to maintain access. In one case, an adversary moved from initial access to nine additional endpoints in just 11 hours.
Context & Attribution
- Tactics: The methods used—including “email bombing” and fake support calls—are highly consistent with tradecraft previously attributed to the Black Basta ransomware group and FIN7.
- Customization: While Havoc is an open-source framework, these attackers use heavily modified versions to blend in with trusted services like Microsoft Graph API and SharePoint.