- Company
Silent Push Inc. ©2025
Security automation platforms are only as effective as the intelligence behind them. SOAR platforms rely on high fidelity data to make decisions, prioritize alerts, and take meaningful action.
This session explores how Silent Push provides the data foundation that enables SOAR workflows to make faster decisions, identify malicious infrastructure earlier, and respond with confidence:
SIEM platforms are only as powerful as the intelligence that feeds them.
Modern SIEMs rely on enriched, contextual data to detect threats, correlate events, and reduce dwell time.
This session explores how Silent Push provides Indicators of Future Attack (IOFA) and over 70 contextual attributes per IP or domain to enable SIEMs to detect malicious infrastructure before attacks occur, improve correlation of suspicious activity, and support a truly proactive approach to cyber defense.
Learn how to:
Stay ahead of attacks by turning Silent Push’s extensive data into an early warning system.
What you will learn in this webinar:
Stay ahead of attacks by turning Silent Push’s extensive data into an early warning system.
AdaptixC2 is a new and emerging extensible post-exploitation and adversarial emulation framework designed for penetration testers. Security researchers and red teams (groups of security experts authorized to act as adversaries, performing simulated attacks against an organization to identify vulnerabilities and test defensive capabilities) frequently utilize this open-source tool, which can be downloaded for free from GitHub.
Our threat team first observed AdaptixC2 being abused during our research into the CountLoader threat, which is highlighted in our August 2025 TLP: Amber report, exclusive for Enterprise clients, and the September 2025 blog that followed. We found malicious AdaptixC2 payloads being served from attacker infrastructure utilizing the CountLoader malware, indicating a preference for both tools.
Apart from creating detection signatures for CountLoader infrastructure, our team has also developed signatures to detect AdaptixC2, ensuring comprehensive coverage for our customers. Coincidentally, shortly after we added those signatures to our detection methods, several public reports highlighted a surge in the use of AdaptixC2 across global ransomware campaigns.
AdaptixC2 is an extensible post-exploitation and adversarial emulation framework created for penetration testers. For flexibility, the AdaptixC2 server is written in Golang. The GUI Client is written in C++ and QT so that it can be used on either Linux, Windows, or macOS operating systems. The following GitHub repository provides the latest information on the AdaptixC2 framework. (Source: https://github.com/Adaptix-Framework/AdaptixC2).

In our recent client report on CountLoader, we detailed how a new malware loader was dropping malicious AdaptixC2 payloads. This prompted us to create a few dedicated Indicators Of Future Attack™ (IOFA™) feeds to cover both threats.
Our CountLoader research provided clear evidence that, beyond its use as an ethical pen-test tool, AdaptixC2 is being used by cyber criminals. This finding was also underscored in a recent DFIR Report, which observed AdaptixC2 use by an Akira ransomware affiliate.
According to a CISA bulletin, Akira ransomware has been used in attacks since March 2023 against a wide range of businesses and critical infrastructure providers in North America, Europe, and Australia. Akira has affected over 250 organizations and claimed an estimated $42 million (USD) in ransomware proceeds.
Follow the Silent Push threat intelligence team on LinkedIn and X/Twitter for our latest research findings.
Our CountLoader research initially provided us with a C2 IP address, 64[.]137[.]9[.]118, which was the starting point for our research into AdaptixC2’s use by threat actors. Using the Silent Push Web Scanner, our team created a technical fingerprint to track AdaptixC2 servers.
Unfortunately, for operational security (OPSEC) purposes, we are unable to share any technical details on the fingerprints outside of our client base. If you are interested in proactive protection against these threats, please reach out to our sales team.
The individual making the most commits (changes) to the AdaptixC2 Framework repository is an individual who goes by the handle “RalfHacker.”

In the image below, taken from their GitHub biography, RalfHacker presents themselves as a penetration tester, red team operator, and—most importantly from our perspective—as a “MalDev,” or a malware developer. This, understandably, sparked further investigation.
![Screenshot of github[.]com/RalfHacker](https://www.silentpush.com/wp-content/uploads/adaptix-image-3-ralf-hacker.png)
Our team was able to recover several email addresses for GitHub accounts linked to “RalfHacker.” The first email address recovered was: cybersecurityaaron@protonmail[.]com, and an even older email address used by RalfHacker: hackerralf8@gmail[.]com.
From information obtained through an Open-Source Intelligence (OSINT) site, intelx.io, we confirmed this email address was also found listed in a leaked database belonging to a known hacking forum.

A Telegram account then led us to a large Telegram group, named after “Ralf Hacker,” advertising the v0.6 update to AdaptixC2 with a pinned message in Russian containing hashtags related to Active Directory and (roughly machine-translated) APT & ATM materials/resources.

It is interesting to note that RalfHacker makes its announcements primarily in Russian. This aligns with the strong ties to Russia our team discovered during the course of our CountLoader research, though it is not a definitive link by itself. Our team has compiled additional details on this individual’s activity, which, for OPSEC purposes, are only available to our enterprise customers.

We also identified a related second Telegram channel that promotes just the AdaptixC2 framework: t[.]me/AdaptixFramework.
Based on the information we have available, there is insufficient evidence for us to conclusively determine the extent of RalfHacker’s involvement in malicious activity tied to AdaptixC2 or CountLoader at this time. However, threat actors often mask their cyber criminal activities under the guise of “red teaming,” or ethical hacking, when communicating publicly with other threat actors. RalfHacker’s own page aligns with this practice, featuring the brazen “maldev” advertisement.
Other legitimate red team tools, such as “evilginx2,” which corporate developers maintain, are also heavily utilized by threat actors. Separating malicious from ethical use requires significantly more evidence from defenders, which adds another layer of obfuscation for cyber criminals.
RalfHacker’s ties to Russia’s criminal underground, via the use of Telegram for marketing and the tool’s subsequent uptick in utilization by Russian threat actors, all raise significant red flags for our team.
Given that AdaptixC2, which RalfHacker regularly develops and maintains, remains in active use by cyber criminals, our team assesses with moderate confidence that ties between the two are non-trivial and worthy of inclusion and continued observation.
Our enterprise customers have access to the exclusive report we created for this campaign. If you would like to learn more about our capabilities for tracking adversarial frameworks—or how you can hunt for them on our platform—we encourage you/your organization to reach out to our team for a demonstration of Silent Push cyber defense technology.
Connect with our platform experts for an overview of the Silent Push Enterprise Edition platform. We are happy to provide you with a tailored walkthrough for your specific use case, along with insights into integrations and API capabilities.
Our threat team will continue to track and examine AdaptixC2’s infrastructure, as well as that of other post-exploitation frameworks, for malicious behavior and report new findings as our research progresses.
If you or your organization has any information to share on this topic or any related ones, we would love to hear from you.
The Silent Push Threat Intelligence team discussed what we see as some of the greatest threats and motivators the global community will encounter in the New Year. Here are our 2026 predictions:



We’re now several years since the 911 S5 Proxy botnet takedown, which affected 19 million devices. As we expected, threat actors are continuing to scale up similar networks by bundling their illicit residential VPN software with malware, freeware, and other schemes to get them deployed across both home and corporate networks.




These trends paint a dark picture of an increasingly complex and murky landscape that organizations and their defenders will be forced to navigate, whether they are ready or not, in the New Year. At Silent Push, we believe that adopting preemptive and proactive methods and mindsets is the best way to secure an organization and keep businesses operating unimpeded in the face of relentless, ever-evolving adversarial infrastructure.
Follow the Silent Push threat intelligence team on LinkedIn and X/Twitter for our latest research findings.
Sign up for a free Silent Push Community Edition account to gain a powerful introduction to our preemptive threat hunting solution that provides a complete view of emerging threat infrastructure in real-time, exposing malicious intent through our Indicators of Future Attack™.
Alternatively, if you’re interested in discussing how to experience the platform and the cybersecurity benefits it can offer, schedule some time to talk with our threat-hunting experts. We can demonstrate how our Indicators of Future Attack™ can provide your team with the visibility to preempt threats, reduce noise, and drive faster, more confident security decisions—all through one unified platform.
Back in June, Silent Push provided our enterprise customers with unpublished infrastructure related to the Chinese APT group Salt Typhoon, giving our customers the early visibility and historical reach-back they needed for both security and their own investigations. At the time, our team flagged the infrastructure due to low-density IP associations, technical fingerprints we are still unable to fully disclose, and operational patterns consistent with Salt Typhoon and other Chinese APT actors’ campaigns.
Background: Also referred to as “GhostEmperor,” “FamousSparrow,” “Earth Estries,” and “UNC2286”, Salt Typhoon is a Chinese threat actor believed to be operated by the PRC’s Ministry of State Security (MSS). This group has conducted numerous high-profile cyber-espionage campaigns against the United States, as well as against over 80 other countries across the world that are geopolitical competitors with China.

Several months later in October, Darktrace referenced Silent Push in their findings of initial access, confirming that the domain, “aar.gandhibludtric[.]com (38.54.63.75)”, was observed in active use as a Command-and-Control (C2) host for a compromised endpoint.
According to their report, Salt Typhoon leveraged LightNode VPS infrastructure, using both HTTP and a custom TCP protocol to communicate. Their HTTP traffic included POST requests with Internet Explorer user agents and URI patterns like /17ABE7F017ABE7F0, aligning with known Salt Typhoon behavior.
The domain found by Darktrace, aar.gandhibludtric[.]com, was first seen by Silent Push resolving to 38.54.63.75 in early May 2025. This domain initially stood out to us as part of a cluster of novel setups indicating threat actor preparation. Our latest findings, and the commendable work by Darktrace, have only confirmed this.
| Domain | Observation Timeframe and Related Low-Density IP Address |
| aar.gandhibludtric[.]com | 2025-05-05 to 2025-06-05— 38.54.63.75 |
We are now comfortable releasing our latest breakthrough to the public:
New IOFA™ Feeds, available only to Silent Push Enterprise Customers, which provide ongoing, pre-emptive protection from Salt Typhoon and related Chinese APT threats!
Please note: for operational security reasons, and to ensure the continued safety of our customers, we are unable to publicly release any further details related to these threats. We encourage telecoms and other organizations concerned about possible intrusion by Chinese APT groups to reach out to us as soon as possible.
Salt Typhoon and related threat groups have a long history of targeting telecommunications and network operators, exploiting their position as gateways to vast volumes of sensitive data and traffic. Once inside a telecom network, attackers can intercept communications, move laterally across interconnected systems, and gain persistent access to downstream customers and infrastructure.
Telecom providers face unique challenges that make them attractive targets:
With the early visibility our IOFA™ feeds provide, telecom security teams could have detected and blocked domains like aar.gandhibludtric[.]com weeks to months before they were weaponized or appeared in public reporting. This type of proactive stance allows operators to:
It bears repeating that our telemetry is revealing new Salt Typhoon infrastructure, that has not yet been reported elsewhere, on an ongoing basis. Telecom organizations using Silent Push would already have had the information they needed to act on these types of indicators, enabling faster and more informed decisions with which to protect their networks and customers.
Read our public technical deep dive on this topic from September, here, and if your organization could have used that information back in June, reach out to us here.
Silent Push will continue to track Salt Typhoon’s infrastructure and activity, adding any newly found domains and IP addresses to our Indicator of Future Attack (IOFA)™ feeds and sharing our technical findings and research with our customers. As noted earlier, we have shared as much information in this blog as we can at this time.
Our enterprise clients have access to additional technical information and insights on Salt Typhoon, UNC4841, and other related Chinese threat actors, and can look forward to a new report on our latest successes in the coming days.
If you or your organization has any information you would like to share about Salt Typhoon, UNC4841, or other Chinese-associated threat actor groups, we would love to hear from you.
Silent Push provides unmatched visibility into pre-operational threat actor activity. If you are responsible for defending telecom or carrier networks, schedule a short demo with our team to see how Silent Push can deliver early warning on emerging threats and malicious infrastructure.