BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

AdaptixC2 Framework Adopted by Russian-Linked Ransomware Groups

AdaptixC2: The Emerging Open-Source C2 Framework Used by Russian Ransomware Groups and Cybercriminals

  • The open-source command-and-control (C2) framework AdaptixC2 is increasingly used by threat actors, including Russian Ransomware groups.
  • AdaptixC2 supports encrypted communications and various post-exploitation features for controlling infected devices.
  • The framework was publicly released in August 2024 by a GitHub user called RalfHacker.
  • Groups linked to Fog and Akira ransomware and an initial access broker use AdaptixC2 and related tools in attacks.
  • Concerns arise over potential criminal ties due to the framework’s growth in underground activity and its promotion on Telegram channels.

The open-source command-and-control framework called AdaptixC2 is seeing expanded use by cybercriminals, including groups associated with Russian ransomware gangs. The framework, designed for penetration testing, provides a variety of features to control compromised systems.

- Advertisement -

AdaptixC2 supports fully encrypted communications, remote command execution, credential and screenshot management, and a remote terminal. The server component is written in Golang, while its graphical user interface (GUI) client uses C++ QT for cross-platform compatibility.

The framework was initially released in August 2024 by a GitHub user known as RalfHacker, who describes himself as a penetration tester and Malware developer. The release is publicly available on GitHub.

Security researchers at Palo Alto Networks Unit 42 recently analyzed AdaptixC2, describing it as a modular tool that offers comprehensive control over infected devices. They noted its usage in fake Microsoft Teams help desk support scams and AI-generated PowerShell scripts. The framework is also employed by groups tied to the Fog and Akira ransomware operations and an initial access broker that uses CountLoader for delivering post-exploitation payloads.

Cybersecurity firm Silent Push investigated RalfHacker following a GitHub profile claiming “MalDev” (malware developer) status. They uncovered multiple associated email addresses and a Telegram channel, RalfHackerChannel, which has over 28,000 subscribers. This channel shares posts from the official AdaptixFramework channel.

- Advertisement -

In August 2024, a message on the AdaptixFramework channel mentioned plans to develop a “public C2” tool similar to the well-known Empire framework. While direct involvement of RalfHacker in criminal acts is not confirmed, Silent Push highlighted potential links to Russia’s cybercrime underground due to Telegram marketing and increased use by Russian threat actors.

The Hacker News reached out to RalfHacker for comment and will provide updates if a response is received.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

BitGo Q1 Loss Widens Despite Revenue Jump, Client Growth

BitGo reported a Q1 2026 net loss of $60.7 million, widened by $53.7 million...

Linux Fragnesia CVE-2026-46300 LPE Vulnerability Uncovered

A new Linux kernel vulnerability dubbed "Fragnesia" (CVE-2026-46300) allows unprivileged local attackers to gain...

BRICS Shun US Dollar for $214B Yuan Trade Amid Sanctions

BRICS nations Russia and Iran settled $214 billion in trade using the Chinese yuan...

Moody’s: Digital Shift Will Start Slow, Then Go Fast

Major US banks and financial intermediaries expect a digital financial transition to start slowly,...

Coinbase CEO Backs Revised Crypto Clarity Act Ahead of Senate Markup

Coinbase CEO Brian Armstrong endorses the latest bipartisan Digital Asset Market Clarity Act ahead...

Must Read

The 13 Best Crypto Advertising Networks to Grow Your Project

TABLE OF CONTENTSWhy Traditional Ad Networks (Like Google & Facebook) Fail CryptoQuick-View Comparison TableHow to Choose the Right Crypto Ad Network for Your ProjectBest...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading