---
title: "Fake Tech Support Delivers Havoc Command & Control"
url: https://daily.dev/posts/fake-tech-support-delivers-havoc-command-control-ixphqqdsq
source_url: https://www.huntress.com/blog/fake-tech-support-havoc-command-control
type: article
source: "Huntress Blog"
published: 2026-05-31T07:43:27.749Z
updated: 2026-05-31T08:09:36.843Z
tags: ["security", "malware"]
reading_time: 31
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Fake Tech Support Delivers Havoc Command & Control

**[Huntress Blog](https://daily.dev/sources/huntress-blog)** · 31 min read · 0 upvotes · 0 comments

## Summary

Huntress researchers detail a February 2026 intrusion campaign where adversaries used fake IT support calls and email spam to trick users into granting remote access, then deployed a heavily modified Havoc C2 framework across five organizations. The attack chain involved DLL sideloading using legitimate signed binaries (ADNotificationManager.exe, DLPUserAgent.exe, WerFault.exe), a custom loader employing Hell's Gate and Halo's Gate indirect syscall techniques to bypass EDR hooks, and ChaCha20-encrypted shellcode stored in a license.key file. The Havoc Demon agent was customized beyond stock defaults — notably adding a registry-based fallback C2 mechanism not present in the original framework. Lateral movement reached nine additional endpoints within eleven hours, with persistence established via scheduled tasks and two legitimate RMM tools (Level RMM and XEOX). The campaign shares TTPs with previously documented Black Basta/FIN7 activity, including registry-stored C2 parameters and extensive DLL sideloading. Full IOCs, YARA-compatible detection rules, and remediation recommendations are provided.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.huntress.com/blog/fake-tech-support-havoc-command-control>

## Similar posts on daily.dev

- [Operation TrueChaos: 0-Day Exploitation Against Southeast Asian Government Targets](https://daily.dev/posts/operation-truechaos-0-day-exploitation-against-southeast-asian-government-targets-boghs0d4o) · Check Point Research · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/fake-tech-support-delivers-havoc-command-control-ixphqqdsq)
