Russian Ransomware Gangs Weaponize Open-Source AdaptixC2 for Advanced Attacks
Oct 30, 2025
Malware / Cybercrime
 The open-source command-and-control (C2) framework known as AdaptixC2  is being used by a growing number of threat actors, some of whom are related to Russian ransomware gangs.  AdaptixC2 is an emerging extensible post-exploitation and adversarial emulation framework  designed for penetration testing. While the server component is written in Golang, the GUI Client is written in C++ QT for cross-platform compatibility.  It comes with a wide range of features, including fully encrypted communications, command execution, credential and screenshot managers, and a remote terminal, among others. An early iteration was publicly released  by a GitHub user named " RalfHacker " ( @HackerRalf  on X) in August 2024, who describes themselves as a penetration tester, red team operator, and "MalDev" (short for malware developer).   In recent months, AdaptixC2 has been adopted by various hacking groups, including threat actors tied to the Fog  and Akira  ransomware operations, as ...