Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fake IT Support Scam Spreads Havoc C2 Framework

Fake IT Support Scam Spreads Havoc C2 Framework

Posted on March 3, 2026 By CWS

Cybersecurity experts have detected a sophisticated campaign in which attackers are posing as IT support to distribute the Havoc command-and-control (C2) framework. This strategy serves as a precursor to either data theft or ransomware attacks.

This campaign, identified by Huntress last month, affected five partner organizations. It involved spam emails and follow-up phone calls from fake IT help desks, initiating a complex malware delivery chain. According to researchers Michael Tigges, Anna Pham, and Bryan Masters, one incident saw attackers access nine additional endpoints within eleven hours, deploying custom Havoc Demon payloads and legitimate remote management tools to sustain their presence. This rapid lateral movement suggests a clear intent towards data theft or ransomware deployment.

Background and Tactics

The tactics used in these attacks resemble previous email bombing and phishing operations attributed to the Black Basta ransomware group. Despite this group’s apparent inactivity following a leak of its internal communications last year, the persistence of their methods indicates two possibilities. Either former Black Basta affiliates are engaging in other ransomware operations, or competing threat actors are mimicking their techniques to execute social engineering and gain initial entry.

The attack method begins with a spam campaign designed to inundate targets’ inboxes with junk mail. Subsequently, the attackers, pretending to be IT support, contact victims and deceive them into allowing remote access via Quick Assist or tools like AnyDesk to resolve supposed issues.

Execution and Evasion

Once access is obtained, attackers swiftly open a web browser to a counterfeit page hosted on Amazon Web Services (AWS), mimicking Microsoft. Here, victims are instructed to input their email to update Outlook’s anti-spam rules. Clicking “Update rules configuration” on this bogus page runs a script prompting users to enter their password, thus enabling the theft of credentials while enhancing the interaction’s credibility.

Further, the assault entails downloading a fake anti-spam patch, leading to the execution of legitimate binaries like “ADNotificationManager.exe” to sideload a malicious DLL. This DLL is designed to evade defenses and run the Havoc shellcode payload by spawning a thread with the Demon agent. Notably, one DLL, “vcruntime140_1.dll,” uses advanced evasion tactics to circumvent security software.

Persistence and Implications

After deploying the Havoc Demon on the initial host, attackers expanded their reach across the victim’s network. While initial social engineering and malware delivery showed innovative methods, the subsequent manual actions were relatively straightforward. Scheduled tasks were created to persistently launch the Havoc Demon payload upon each system reboot, granting attackers ongoing remote access.

Notably, attackers also employed legitimate remote monitoring and management (RMM) tools like Level RMM and XEOX on some compromised hosts, diversifying their persistence efforts. The campaign underscores how attackers are willing to impersonate IT staff and engage victims directly to increase their success rate. Techniques once reserved for major firms or state-backed activities are now commonplace, with customized malware bypassing standard security signatures.

As attacks rapidly progress from initial compromise to extensive network penetration, utilizing multiple persistence methods, organizations must remain vigilant. This deceptive IT support strategy exemplifies how modern adversaries integrate sophistication at every phase: using social engineering to gain entry, DLL sideloading for stealth, and varied persistence techniques to endure remediation.

The Hacker News Tags:Black Basta, Cybersecurity, data exfiltration, Havoc C2, IT support scam, Malware, Phishing, Ransomware, social engineering, spam campaign

Post navigation

Previous Post: Google Introduces MTCs to Secure HTTPS from Quantum Risks
Next Post: Hacktivist Surge Amid US-Israel Strikes on Iran

Related Posts

Cybercriminals Abuse Google Cloud Email Feature in Multi-Stage Phishing Campaign Cybercriminals Abuse Google Cloud Email Feature in Multi-Stage Phishing Campaign The Hacker News
Why CISOs Must Rethink Incident Remediation Why CISOs Must Rethink Incident Remediation The Hacker News
Trellix Reports Source Code Breach Incident Trellix Reports Source Code Breach Incident The Hacker News
FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks The Hacker News
Cracked Software and YouTube Videos Spread CountLoader and GachiLoader Malware Cracked Software and YouTube Videos Spread CountLoader and GachiLoader Malware The Hacker News
45 Previously Unreported Domains Expose Longstanding Salt Typhoon Cyber Espionage 45 Previously Unreported Domains Expose Longstanding Salt Typhoon Cyber Espionage The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Latest Android Update Fixes Zero-Day and 123 Vulnerabilities
  • Mustang Panda Launches Complex PlugX RAT Cyberattack
  • Security Flaw in Microsoft Android Apps Exposes Billions
  • Critical PAN-OS Vulnerability Exploited, CISA Warns
  • Anthropic Expands AI Security Program to 150 New Partners

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Latest Android Update Fixes Zero-Day and 123 Vulnerabilities
  • Mustang Panda Launches Complex PlugX RAT Cyberattack
  • Security Flaw in Microsoft Android Apps Exposes Billions
  • Critical PAN-OS Vulnerability Exploited, CISA Warns
  • Anthropic Expands AI Security Program to 150 New Partners

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark