Dark Mythic C2 Agent with BOF Loader
Score: 7/10

Dark Mythic C2 Agent with BOF Loader

The ServiceNow Red Team developed Dark, an open-source Mythic C2 agent written in Crystal that features in-memory Beacon Object File (BOF) execution for macOS and Linux.

Executive Summary

The ServiceNow Red Team has released 'Dark', a specialized Command and Control (C2) agent integrated with the Mythic framework. Operationally proven since 2024, Dark is distinguished by its ability to execute Beacon Object Files (BOFs) entirely in-memory on macOS (including Apple Silicon) and Linux platforms, bypassing traditional disk-based detection mechanisms.

Technically, the agent is written in the Crystal language and utilizes a custom in-memory loader to handle ELF and Mach-O object files, replicating complex linker functions such as global offset table (GOT) management and thunk table bridging for CPU jumps. It implements security features like Two Person Integrity (TPI) for sensitive commands and automated artifact tracking to log indicators of compromise (IOCs) such as file reads and writes.

This development is significant as it brings mature Windows-centric tradecraft—specifically reflective in-memory execution—to macOS and Linux environments where EDR detection for such techniques is often less mature. The ability to load external BOFs dynamically means the initial payload remains lean and difficult to signature while retaining extensive post-exploitation capabilities.

Key Details

Threat Name

Dark Agent

Affects

—

Adversary

ServiceNow Red Team

Malware/Tools

Dark, Poseidon, Cobalt Strike, BOFHound

Report Score

7out of 10
Quality Score
Good
IOC Quality2
TTP Details9
Detection Guidance6
Enterprise Relevance8
Clarity & Structure9
Technical Depth9

Sources