As cited
Copy frozen at (site build).
threat intel
Fake Tech Support Delivers Havoc Command & Control
Threat actors are using fake technical support schemes to distribute a customized version of the Havoc command and control (C2) framework. The attacks employ advanced evasion techniques including DLL sideloading, syscall evasion methods like HellsGate, and legitimate remote monitoring and management (RMM) tools to establish persistent access to victim systems.
Why it matters: Organizations receiving unsolicited tech support contacts face risk of malware deployment and persistent compromise; security teams should educate users on social engineering tactics and monitor for suspicious RMM tool activity.
- Source published
- First seen by Cybersecurity Tracker