Skip to main content
Mallory
Back to malware
MalwareUsed by 2 actorsExploits 4 CVEs

Mythic Agent

Mythic Agent is a post-exploitation implant built on the Mythic C2 framework that provides remote-access capabilities including command execution, reconnaissance, file exfiltration, lateral movement, C2 communication, payload delivery, and additional plugin loading. The content links it primarily to RomCom activity in 2025, including campaigns exploiting the WinRAR zero-day CVE-2025-8088 and a separate campaign in which SocGholish fake-update infections delivered a targeted Mythic Agent loader to U.S. companies supporting Ukraine, including a U.S. civil engineering firm. RomCom is described as Russia-aligned and also tracked as Storm-0978, Tropical Scorpius, and UNC2596; Arctic Wolf assessed related targeting patterns as aligning with GRU Unit 29155. In the WinRAR exploitation chains, malicious RAR archives disguised as CVs or job applications used alternate data streams to drop LNK and DLL/EXE payloads, including a Mythic Agent chain in which Updater.lnk established persistence via COM hijacking by setting HKCU\SOFTWARE\Classes\CLSID{1299CF18-C4F5-4B6A-BB0F-2299F0398E27}\InprocServer32 to %TEMP%\msedge.dll. The msedge.dll payload decrypted embedded AES-encrypted shellcode and launched the Mythic agent; one observed C2 endpoint was https://srlaptop[.]com/s/0.7.8/clarity.js. Arctic Wolf also described a SocGholish-delivered RomCom loader disguised as msedge.dll that executed only if the victim Active Directory domain matched a hardcoded value, then decrypted shellcode identified as a Mythic dynamichttp agent; a reported C2 URL in that activity was https://imprimerie-agp[.]com/s/0.7.8/clarity.js. The malware was observed alongside other RomCom payloads such as SnipBot and RustyClaw. Separately, the content notes Mythic Agent was found on a compromised Microsoft Exchange server in a 2025 investigation involving likely Erudite Mogwai/Space Pirates activity, where it was listed among multiple co-resident malware families; in that reporting, Mythic Agent is attributed to GOFFEE.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

4 CVES
CVE-2021-34473ProxyShell pre-auth SSRF/authentication bypass in Microsoft Exchange AutodiscoverExploited in the wild

...источником их заражения оказался почтовый сервер Exchange, который оказался скомпрометированным еще летом 2024 года с помощью эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).

via rt solarrt-solar.ru
CVE-2021-34523Microsoft Exchange PowerShell Backend Elevation of Privilege (ProxyShell)Exploited in the wild

...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).

via rt solarrt-solar.ru
CVE-2025-8088WinRAR Windows Path Traversal via NTFS Alternate Data StreamsExploited in the wild

The vulnerability, tracked as CVE-2025-8088, affects all Windows versions of WinRAR up to 7.12 ... a path traversal bug that leverages Window’s alternate data streams (ADS) feature to circumvent normal file extraction safeguards.

via techrepublic com securitytechrepublic.com
CVE-2021-31207Post-auth arbitrary file write in Microsoft Exchange Server (ProxyShell)Exploited in the wild

...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).

via rt solarrt-solar.ru
THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
RomCom

Mythic Agent is a sophisticated implant built on the Mythic C2 framework, designed to grant attackers powerful remote-access capabilities, including command execution, reconnaissance, file exfiltration, lateral movement, and additional plugin loading.

via cso onlinecsoonline.com
Paper Werewolf

...были обнаружены различные файлы вредоносного ПО: ... Mythic Agent (GOFFEE)

via rt solarrt-solar.ru
MITRE ATT&CK

Techniques & procedures

7 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1190Exploit Public-Facing ApplicationEvidence1

«…источником их заражения оказался почтовый сервер Exchange, который оказался скомпрометированным еще летом 2024 года с помощью эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).»

Execution

2 techniques
T1059Command and Scripting InterpreterEvidence1
TacticExecution

The backdoor used by the group is capable of executing commands and downloading additional modules to the victim’s machine.

T1203Exploitation for Client ExecutionEvidence1
TacticExecution

ESET researchers have discovered a previously unknown zero-day vulnerability in WinRAR being exploited in the wild by Russia-aligned group RomCom... The vulnerability, CVE-2025-8088, is a path traversal vulnerability... Disguised as an application document, the weaponized archives exploited a path traversal flow to compromise its targets.

T1055Process InjectionEvidence1

PowerTaskel загружает бинарный агент с командного сервера, внедряет его в память своего процесса и запускает в отдельном потоке

Stealth

3 techniques
T1055Process InjectionEvidence1

PowerTaskel загружает бинарный агент с командного сервера, внедряет его в память своего процесса и запускает в отдельном потоке

T1564.004NTFS File AttributesEvidence1
TacticStealth

The vulnerability, CVE-2025-8088, is a path traversal vulnerability, which is made possible via the use of alternate data streams.

T1620Reflective Code LoadingEvidence1
TacticStealth

Третий скрипт отвечает за выделение памяти, загрузку шелл-кода из HTA-файла ... и передачу управления загруженному шелл-коду

T1105Ingress Tool TransferEvidence1

The backdoor used by the group is capable of executing commands and downloading additional modules to the victim’s machine.

INDICATORS OF COMPROMISE

IOCs tracked for this family

3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Hashes
3 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.md5●●●●●●●●●●●●View more in app1 year ago
hash.sha256●●●●●●●●●●●●View more in app1 year ago
hash.sha1●●●●●●●●●●●●View more in app1 year ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching3

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities4

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping7

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.