AdaptixC2 Defender

In July 2025 AdaptixC2 moved from red team lab to real breaches; this guide shows how defenders can spot it fast using Yara, C2 Feeds, User agent etc.

What it is? AdaptixC2 is an open-source post-exploitation/C2 framework and adversarial emulation framework made for penetration testers. The Adaptix server is written in Golang and to allow operator flexibility. The GUI Client is written in C++ QT, allowing it to be used on Linux, Windows, and MacOS

AdaptixC2’s functionality is identical to traditional penetration frameworks such as Cobalt Strike, Sliver, Havoc, and Mythic.

Timeline

  • Jan 2025 – v0.1 released
  • May 2025 – First seen on ThreatFox and MalwareBazaar. Observed in the wild by Symantec and Unit 42
  • Jul 2025 – Observed in the wild by The DFIR Report and QiAnXin
  • Aug 2025 – v0.8 released
  • Dec 2025 – v1.0 released

Known In-the-Wild Incidents

A compact, source-linked index of public reports where AdaptixC2 appears in real intrusions.

Blog Source Publish Date When it was used?
Cyber Warfare Amidst Gold’s Skyrocketing Price: UTG-Q-010 Group’s Supply-Chain Attack QiAnXin TI Center 4 Sep, 2025 Jul 2025
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira The DFIR Report 5 Aug, 2025 Jul 2025
AdaptixC2: A New Open-Source Framework Leveraged in Real-World Attacks Unit 42 10 Sep, 2025 May 2025
Unusual Fog ransomware activity Symantec (Broadcom) 12 Jun, 2025 May 2025
Last updated: 2025-09-20

Detection

Default user agent
If the actor did not change it, hunt for this in your web logs:
`Mozilla/5.0 (Windows NT 6.2; rv:20.0) Gecko/20121202 Firefox/20.0

Based on the User agent website this maps to Firefox browser running on Windows 8, which should be rare in most networks.
Treat matches as suspicious and pivot by source IP, URI path, and user account.

Yara Rules
AdaptixC2 yara rules from then Unit42 blog, mirrored for convenience: AdaptixC2 YARA rules — GitHub.

Config extractor

The config extractor (by the Unit 42 team) is here: AdaptixC2 config extractor — GitHub.
This executable was created with the latest AdaptixC2 version and extracts the C2 cleanly.

This exe file was created using the latest AdaptixC2 version and it works perfectly fine , extract the C2 without any issue.

C2 Feeds

Hash Feed

References

Thanks for reading. Feel free to connect with me on or LinkedIn for any suggestions or comments.

For more updates and exclusive content, subscribe to our newsletter. Stay sharp. Keep defending.😊

Join for free. Practical security bits you can act on the same day. No theory, no fluff.

No spam. Unsubscribe anytime.

keyboard_arrow_up