In July 2025 AdaptixC2 moved from red team lab to real breaches; this guide shows how defenders can spot it fast using Yara, C2 Feeds, User agent etc.
What it is? AdaptixC2 is an open-source post-exploitation/C2 framework and adversarial emulation framework made for penetration testers. The Adaptix server is written in Golang and to allow operator flexibility. The GUI Client is written in C++ QT, allowing it to be used on Linux, Windows, and MacOS
AdaptixC2’s functionality is identical to traditional penetration frameworks such as Cobalt Strike, Sliver, Havoc, and Mythic.
Timeline
- Jan 2025 – v0.1 released
- May 2025 – First seen on ThreatFox and MalwareBazaar. Observed in the wild by Symantec and Unit 42
- Jul 2025 – Observed in the wild by The DFIR Report and QiAnXin
- Aug 2025 – v0.8 released
- Dec 2025 – v1.0 released
Known In-the-Wild Incidents
A compact, source-linked index of public reports where AdaptixC2 appears in real intrusions.
| Blog | Source | Publish Date | When it was used? |
|---|---|---|---|
| Cyber Warfare Amidst Gold’s Skyrocketing Price: UTG-Q-010 Group’s Supply-Chain Attack | QiAnXin TI Center | 4 Sep, 2025 | Jul 2025 |
| From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira | The DFIR Report | 5 Aug, 2025 | Jul 2025 |
| AdaptixC2: A New Open-Source Framework Leveraged in Real-World Attacks | Unit 42 | 10 Sep, 2025 | May 2025 |
| Unusual Fog ransomware activity | Symantec (Broadcom) | 12 Jun, 2025 | May 2025 |
| Last updated: 2025-09-20 |
Detection
Default user agent
If the actor did not change it, hunt for this in your web logs:
`Mozilla/5.0 (Windows NT 6.2; rv:20.0) Gecko/20121202 Firefox/20.0
Based on the User agent website this maps to Firefox browser running on Windows 8, which should be rare in most networks.
Treat matches as suspicious and pivot by source IP, URI path, and user account.
Yara Rules
AdaptixC2 yara rules from then Unit42 blog, mirrored for convenience: AdaptixC2 YARA rules — GitHub.
Config extractor
The config extractor (by the Unit 42 team) is here: AdaptixC2 config extractor — GitHub.
This executable was created with the latest AdaptixC2 version and extracts the C2 cleanly.
This exe file was created using the latest AdaptixC2 version and it works perfectly fine , extract the C2 without any issue.
C2 Feeds
- ThreatFox | AdaptixC2 – First Seen – 2025-05-25 18:22:59 UTC
- GitHub – drb-ra/C2IntelFeeds: Automatically created C2 Feeds



