Huntress researchers detail a February 2026 intrusion campaign where adversaries used fake IT support calls and email spam to trick users into granting remote access, then deployed a heavily modified Havoc C2 framework across five organizations. The attack chain involved DLL sideloading using legitimate signed binaries (ADNotificationManager.exe, DLPUserAgent.exe, WerFault.exe), a custom loader employing Hell's Gate and Halo's Gate indirect syscall techniques to bypass EDR hooks, and ChaCha20-encrypted shellcode stored in a license.key file. The Havoc Demon agent was customized beyond stock defaults — notably adding a registry-based fallback C2 mechanism not present in the original framework. Lateral movement reached nine additional endpoints within eleven hours, with persistence established via scheduled tasks and two legitimate RMM tools (Level RMM and XEOX). The campaign shares TTPs with previously documented Black Basta/FIN7 activity, including registry-stored C2 parameters and extensive DLL sideloading. Full IOCs, YARA-compatible detection rules, and remediation recommendations are provided.