Image for Article: Fake Tech Support Spam Deploys Customized Havoc C2 Across Organizations

Article Details

Title
Article: Fake Tech Support Spam Deploys Customized Havoc C2 Across Organizations
Impact Score
5 / 10
AI Summary (Processed Content)

A new campaign uses fake IT support calls following email spam to trick victims into granting remote access, leading to the deployment of the Havoc C2 framework. The attackers use a fake Microsoft page to harvest credentials and sideload malicious DLLs to execute Havoc payloads, employing advanced evasion techniques. The tactics are consistent with past Black Basta ransomware operations, suggesting either former affiliates or imitators are active. The goal is rapid lateral movement for potential data exfiltration or ransomware deployment. Main topics covered include the social engineering attack chain, the Havoc malware deployment, and the possible connection to known threat actors.

Original URL
https://thehackernews.com/2026/03/fake-tech-support-spam-deploys.html
Source Feed
The Hacker News
Published Date
2026-03-03 17:15
Fetched Date
2026-03-04 13:38
Processed Date
2026-03-04 14:00
Embedding Status
Present
Cluster ID
Not Clustered
Raw Extracted Content