Updates

Check out EvadeX's full list of features here.

ApeX alpha.0

September 2026

  • ApeX C2 Alpha Release: The first public release of ApeX C2, our Stage 0 evasive command and control framework. ApeX executes from backed memory to avoid the class of detections that mainstream C2 frameworks share, and ships evasive out of the box. Access is invite only during alpha. Request access.

v1.3.0

September 2026

  • Callstack Spoofing Options: Choose your callstack spoofing technique per payload. Adds a CET backed variant that operates on hardware with Intel Control-flow Enforcement Technology enabled, alongside the existing spoofing method.

v1.2.0

January 2026

  • Multiple New Execution Techniques: Adding several new execution techniques to further evade EDRs.
  • Advanced Stager: Customizable stager to pre-position inside target processes for improved operational security.

v1.1.1

December 2025

  • Updated Anti-VM: Updated the anti virtual machine checks to be more precise and covert.
  • C2 Specific Resources: Provided in-depth documentation and resources to enable evasive C2 operations.
  • Bug fixes: Squashed some cool and unique bugs.

v1.1.0

October 2025

  • C# Obfuscator: Obfuscate your post-exploitation assemblies to bypass detections.
  • New Execution Technique: Added a new execution technique.
  • EDR Specific Features: Added features to bypass a specific EDR.
  • Bug fixes: Squashed some cool and unique bugs.

v1.0.2

August 2025

  • Bug fixes: Squashed some cool and unique bugs.

v1.0.1

July 2025

  • Bug fixes: Squashed some cool and unique bugs.
  • Private features: Added some features that are better kept private.

v1.0.0

May 2025

  • Language Adding: Choose a language and add strings from APTs known to operate using the selected language.
  • Username Guardrails/Pinning Only allow your payloads to execute when run by a certain user.

beta.6

18 March 2025

  • Callstack Spoofing: Customizable execution and evasion of advanced callstack detections from EDRs.
  • Early Cascade Injection: We now offer process injection using a new and advanced technique.
  • LNK Sideloading: Sideload your DLLs using LNK files for improved social engineering.
  • Pre-Load Network Modules: Load network modules before payload execution to lower detection rates of your shellcode.

beta.5

09 January 2025

  • Generation templates: Predefined customizations to bypass the most common EDRs.
  • Private Persistence Mechanism: A novel persistence mechanism to keep your process running after shutdown and logoff events.
  • Private Execution Timing Options: A novel method for payload execution timing that avoids many detections.
  • Private Execution Method: An undetected method to execute a payload within a built-in & signed process.

beta.4

08 December 2024

  • ClickOnce apps: New output types for improved social engineering.
  • Customizable DLL Proxying: Support for both automatic and manual creation of proxies for easy sideloading of your generated DLLs.
  • Window Hiding: When sideloading an application, easily hide all windows from that process.
  • Delete On Execution: Once your payload is being executed in memory, erase the executable from disk.

beta.3

27 November 2024

  • Updated UI: New, sleek, user interface to make generation more seamless.
  • Documentation: Details on each feature, along with tips & tricks.
  • Emulation Bypass: Avoid your payloads being emulated by defenders with this option.
  • Drip Allocation: Advanced method of allocating memory for your payload.

alpha.21

09 November 2024

  • Base32 encoding: Encode your payload using base32 to avoid entropy checks.
  • XLL & SFX output: New output types for improved social engineering.
  • Custom EXE packer: Already have a payload you want to execute? Use this to avoid detections.
  • Customizable watermarking: Add your unique touch with watermarking sections and the DOS stub.
  • IOC Generation: Get instant Indicators of Compromise (IOCs) bundled with your payloads.
  • Signature reduction: Stripped out a host of common and advanced static and dynamic signatures.

alpha.11

09 October 2024

  • Modified Caro Kann technique: New protections at execution time against memory scanners.
  • Advanced polymorphism: Improved uniqueness and randomness in generated payloads.
  • API key support: A new "Settings" page where you can create and manage API keys!
  • Minor bug fixes and improvements: Better input guardrails and improved error visibility on the Creation Status page.

alpha.00

25 September 2024

  • Modern execution types: Select from threadpools or fibers execution types.
  • Signature emulation: Self sign or steal a signature from an existing binary.
  • Host and domain name checks: Wildcard pattern matching for machine restrictions.
  • ... and much more!