Skip to content

Cobalt Strike

Cobalt Strike is a commercial adversary simulation and red-team framework that is extensively abused by criminal and state-linked threat actors as post-compromise command-and-control infrastructure.

Profile source: Mallory opens in a new tab

Cobalt Strike

Family profile

Cobalt Strike is a commercial adversary simulation and red-team framework that is extensively abused by criminal and state-linked threat actors as post-compromise command-and-control infrastructure. Its Beacon payload is commonly used to maintain access on compromised Windows systems and to support hands-on-keyboard intrusion activity including command execution, reconnaissance, credential access, privilege escalation, lateral movement, persistence, defense evasion, and data exfiltration. In intrusion reporting, Cobalt Strike frequently appears after an initial foothold has already been established by phishing-delivered malware, compromised remote-access credentials, exploited public-facing applications, or other loaders and backdoors.

Operationally, Cobalt Strike is widely used as a follow-on framework in ransomware and access-broker intrusions. It has been observed in activity associated with groups and operations including Clop, Royal, Qilin, RedFoxtrot, and Ransom Cartel, among others, and is often paired with tools such as Qbot, Mimikatz, PowerShell, PsExec, remote administration software, and credential-harvesting utilities. Reported tradecraft includes Beacon-based HTTPS command and control, process injection, service-based persistence, discovery of users, hosts, shares, and domain relationships, and support for lateral movement across enterprise environments. Because it is a legitimate security product that is frequently pirated or misused, detections may classify it as a hacktool or trojan despite its original defensive testing purpose.

Cobalt Strike is most strongly associated with Windows intrusions in the supplied reporting. It is commonly leveraged in enterprise compromises spanning sectors such as banking, healthcare, finance, manufacturing, education, energy, utilities, government, and other corporate environments, especially as an intermediate post-exploitation platform preceding ransomware deployment or data theft.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 31, 2026
Last activity
Aug 7, 2026
Feed role
C2 / Distribution
Host form
155 IP / 40 hostnames

Leading locations

  • CN59
  • US33
  • DE16
  • HK16
  • NL15
  • RU9
  • JP6
  • LU6
  • SG5
  • KR4
  • CA3
  • FR3

Leading providers

  • Shenzhen Tencent Computer Systems Company Limited19
  • Hangzhou Alibaba Advertising Co.,Ltd.16
  • Omegatech LTD7
  • Ghosty Networks LLC6
  • Alibaba (US) Technology Co., Ltd.5
  • China Telecom Beijing Tianjin Hebei Big Data Industry Park Branch5

Infrastructure traits

  • Hosting 156
  • Anycast 6
  • Vpn 3
  • Proxy 1
  • Residential Proxy 1

Samples

Recent associated samples

Reported operators

Threat actors

174 named in public reporting
RedFoxtrot

RedFoxtrot utilise plusieurs méthodes et outils avec DcRat, notamment Cobalt Strike et AsyncRAT, pour l'infiltration et les activités de commande et de contrôle.

ShadowSyndicate

По данным BushidoToken, на инфраструктуре BitLaunch систематически обнаруживаются C2-серверы, в первую очередь CobaltStrike.

FIN7

По данным BushidoToken, на инфраструктуре BitLaunch систематически обнаруживаются C2-серверы, в первую очередь CobaltStrike.

APT29

APT29/Nobelium Cobalt Strike C2 setup with custom certificates and redirections ... APT29/Nobelium Cobalt Strike C2 redirector setup

INC

A distinctive characteristic of INC Ransom’s operations is its extensive use of Living-off-the-Land Binaries (LOLBins), Remote Monitoring and Management (RMM) tools, post-exploitation frameworks such as Cobalt Strike, and custom scripts designed to automate ransomware propagation.

Salt Typhoon

На серверах (за пределами сетевых устройств) Salt Typhoon разворачивает бэкдор GhostSpider (по данным Trend Micro, разработан специально для телеком-сетей), руткит Demodex (kernel-mode), Cobalt Strike, а также SnappyBee и HemiGate.

Mustang Panda

Shellcode: PEB walk + export hash resolver + 54 internal functions ... Second-stage payload (likely a follow-on PE or Cobalt Strike beacon)

StrikeShark

The tool has been spotted delivering Cobalt Strike Beacon, a well known post exploitation framework, onto compromised machines.

Lotus Blossom

Beyond the custom backdoor, the Rapid7 researchers observed the deployment of Cobalt Strike and Metasploit frameworks, noting that the campaign was characterized by highly surgical targeting of government, telecommunications, and financial sectors rather than a broad, indiscriminate infection of the general user base.

DragonForce

they executed a PowerShell command to download additional payloads from a remote location using a Cobalt Strike Beacon, maintaining persistence throughout this process using SystemBC.

TA577

TA577, are a Russia-based threat group that have been reported to deliver payloads including Qbot, IcedID, SystemBC, SmokeLoader, Ursnif, and Cobalt Strike in ongoing phishing campaigns since 2020.

Earth Lusca

Their toolkit includes ShadowPad, Spyder, Cobalt Strike, FunnySwitch, and the BIOPASS RAT, and expanding SprySOCKS to Windows clearly shows continued investment in offensive capability.

APT41

APT41 created the StorSyncSvc service to provide persistence for Cobalt Strike. Cobalt Strike can install a new service.

Tropic Trooper

The malicious samples are called Crowdoor, which, when run, drop CobaltStrike and maintain persistence.

TA866

In several cases, we observed the repeated deployment of Cobalt Strike beacons following successful compromise of organizational networks.

TA505

For C0015, the threat actors used Cobalt Strike and Conti ransomware.

Twelve

In one of the group’s attacks, we discovered traces of the Cobalt Strike framework, which the attackers used to contact their C2 and distribute malicious payloads.

APT32

For their campaigns in Germany, the actor chose Cobalt Strike, a commercially licensed software tool that is generally used for penetration testing and emulates the type of backdoor framework used by Metasploit.

UNC4393

One consistently observed method for establishing and maintaining a foothold was DNS BEACON. According to Cobalt Strike documentation, DNS beacons and listeners can be customized using Malleable C2 profiles.

UNC1151

Reporting throughout 2022 to 2024 described activity in which malicious Excel documents were used to deliver PicassoLoader and Cobalt Strike payloads... Research in a previous campaign found that a Cobalt Strike payload was delivered to targets only if the host IP was located in Ukraine.

Cinnamon Tempest

The threat actors drop Adobe Creative Cloud, Microsoft Edge, and McAfee VirusScan executables vulnerable to DLL hijacking to deploy Cobalt Strike beacons.

Cobalt Group

For their campaigns in Germany, the actor chose Cobalt Strike, a commercially licensed software tool that is generally used for penetration testing and emulates the type of backdoor framework used by Metasploit.

APT19

For their campaigns in Germany, the actor chose Cobalt Strike, a commercially licensed software tool that is generally used for penetration testing and emulates the type of backdoor framework used by Metasploit.

Daggerfly

TAG-112 compromised at least two Tibetan community websites ... This JavaScript prompted visitors to download a fake security certificate, which, when opened, deployed the Cobalt Strike payload.

UAT-6382

Talos has so far found two types of payloads deployed by TetraLoader on the infected endpoints: Cobalt Strike beacons.

TAG-112

TAG-112 compromised at least two Tibetan community websites ... This JavaScript prompted visitors to download a fake security certificate, which, when opened, deployed the Cobalt Strike payload.

TAG-102

TAG-112 compromised at least two Tibetan community websites ... This JavaScript prompted visitors to download a fake security certificate, which, when opened, deployed the Cobalt Strike payload.

Snatch

What we refer to as Snatch malware comprises a collection of tooling, which include a ransomware component and a separate data stealer, both apparently built by the criminals who operate the malware; a Cobalt Strike reverse-shell; and several publicly-available tools...

Conti

Authorities said Lytvynenko engaged in cybercrime after Conti disbanded and its members splintered off into new groups, adding that he “was asleep but within arms’ reach of an open laptop running Cobalt Strike” at the time of his arrest.

TA578

Proofpoint observed Bumblebee dropping Cobalt Strike, shellcode, Sliver, and Meterpreter.

Earth Krahang

Cobalt Strike was also frequently used during the initial stage of an attack. Interestingly, we found that instead of the typical Cobalt Strike usage, Earth Krahang adds additional protection to their C&C server through the adoption of the open-source project RedGuard.

Kimsuky

----[ 2.3 Private Cobalt Strike Beacon Drop Location: mnt/hgfs/Desktop/111/beacon This is a custom Cobalt Strike C2 Beacon.

Chimera

APT29 has obtained and used a variety of tools including Mimikatz, SDelete, Tor, meek, and Cobalt Strike.

WIZARD SPIDER

APT29 has obtained and used a variety of tools including Mimikatz, SDelete, Tor, meek, and Cobalt Strike.

DarkHydrus

APT29 has obtained and used a variety of tools including Mimikatz, SDelete, Tor, meek, and Cobalt Strike.

FIN6

APT29 has obtained and used a variety of tools including Mimikatz, SDelete, Tor, meek, and Cobalt Strike.

SVR

TEARDROP or RAINDROP backdoors would be deployed, which would install a customized Cobalt Strike beacon in the environment, enumerating the domain and allowing for the collection and exfiltration of information of value using hands-on-keyboard techniques.

Sandworm

APT29 has obtained and used a variety of tools including Mimikatz, SDelete, Tor, meek, and Cobalt Strike.

BlackCat

Several Cobalt Strike framework capabilities were utilized by the threat actor throughout the course of the attack, including RDP tunnelling for lateral movement, and process injection for the purposes of execution and evasion.

Velvet Tempest

This industrialization of the cybercrime economy has made it easier for attackers to use ready-made penetration testing and other tools to perform their attacks. Within this category ... attackers using off-the-shelf tools, such as Cobalt Strike...

INDRIK SPIDER

This industrialization of the cybercrime economy has made it easier for attackers to use ready-made penetration testing and other tools to perform their attacks. Within this category ... attackers using off-the-shelf tools, such as Cobalt Strike...

DEV-0365

This industrialization of the cybercrime economy has made it easier for attackers to use ready-made penetration testing and other tools to perform their attacks. Within this category ... attackers using off-the-shelf tools, such as Cobalt Strike...

DEV-0216

This industrialization of the cybercrime economy has made it easier for attackers to use ready-made penetration testing and other tools to perform their attacks. Within this category ... attackers using off-the-shelf tools, such as Cobalt Strike...

DEV-0506

This industrialization of the cybercrime economy has made it easier for attackers to use ready-made penetration testing and other tools to perform their attacks. Within this category ... attackers using off-the-shelf tools, such as Cobalt Strike...

UNG0002

Ultimately, the final stage drops a dangerous Cobalt Strike Beacon directly into memory . This implant establishes an outbound command-and-control connection to a remote server .

UNC3569

This is often followed by the deployment of Cobalt Strike BEACON on the compromised server to establish a foothold for further operations.

Vanilla Tempest

The weaponized tool used by Vice Society is Cobalt Strike, which allows the group to remotely access and control the infected endpoint.

Bl00Dy

The FBI also identified information relating to the download and execution of command and control (C2) malware such as DiceLoader, TrueBot, and Cobalt Strike Beacons, although it is unclear at which stage in the attack these tools were executed.

APT28

MITRE Software: Cobalt Strike.

Lockean

For lateral movement, the threat actor used the Cobalt Strike penetration testing framework, and the freely available Adfind, BloodHound, and BITSadmin tools.

DEV-0413

These attacks used the vulnerability, tracked as CVE-2021-40444, as part of an initial access campaign that distributed custom Cobalt Strike Beacon loaders.

PISTACHE TEMPEST

Les attaquants ont utilisé leur accès de bureau à distance afin d’exécuter deux portes dérobées : SystemBC et Cobalt Strike.

Storm-0390

Around three hours after execution of the initial IcedID malware, a cmd process was spawned from IcedID. This new process began beaconing to a Cobalt Strike server... Using the Cobalt Strike beacon, the threat actor looked up specific domain administrators... copied over a Cobalt Strike beacon to the domain controller and executed it.

Earth Longzhi

The malware used in the incident was a simple but custom Cobalt Strike loader. ... we discovered several custom loaders of Cobalt Strike, including similar samples uploaded in VirusTotal.

UAT-7237

SoundBill can be employed to decode and load any shellcode, including Cobalt Strike.

TEMP.Veles

Dragos has also observed entities associated with XENOTIME experimenting with the Cobalt Strike penetration testing framework.

UNC2628

Across all known intrusions, UNC2628 has made heavy use of the Cobalt Strike framework and BEACON payloads.

GroupCC

The malware used in the incident was a simple but custom Cobalt Strike loader. ... we discovered several custom loaders of Cobalt Strike, including similar samples uploaded in VirusTotal.

Storm-0501

Cobalt Strike (license ID "666", packed with Themida) launched via regsvr32.exe or rundll32.exe.

Storm-0257

CERT-UA said the malware gathers details including the computer name, operating system version, user account information, and running processes. The agency also warned that compromised systems could later receive a payload linked to the offensive hacking framework Cobalt Strike, a legitimate penetration-testing tool frequently abused by cybercriminals and state-backed groups.

FrostyNeighbor

Operators then manually decide whether to deliver a third-stage payload, typically a Cobalt Strike beacon, to high-value targets.

TA445

The name comes from the fact that it retrieves a Cobalt Strike beacon, from an attacker-controlled environment, disguised as a renderable image or hidden in a web-associated file type, like CSS, JS, or SVG.

PUSHCHA

The name comes from the fact that it retrieves a Cobalt Strike beacon, from an attacker-controlled environment, disguised as a renderable image or hidden in a web-associated file type, like CSS, JS, or SVG.

MirrorFace

MirrorFace has used tools including the Secure Copy Protocol (SCP) client from PuTTY and Cobalt Strike.

FIN10

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

BRONZE BUTLER

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

TeamTNT

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

CopyKittens

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

LazyScripter

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

TA2541

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Poseidon Group

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

UNC3886

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Blue Mockingbird

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Storm-1811

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

DarkVishnya

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

APT33

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Handala

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Gorgon Group

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Scattered Spider

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

ToddyCat

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

GALLIUM

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

MoustachedBouncer

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

SideWinder

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Stealth Falcon

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Molerats

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Gallmaker

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Medusa Group

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

TA459

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

APT38

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Gamaredon Group

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

FIN13

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

OilRig

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Lazarus

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

HEXANE

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Tonto

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

FIN8

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Dragonfly

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

APT5

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

GOLD SOUTHFIELD

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Winter Vivern

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Volt Typhoon

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Turla

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

APT39

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

menuPass

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

APT3

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Silence

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Threat Group-3390

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Confucius

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Ember Bear

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Inception

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Magic Hound

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Patchwork

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Fox Kitten

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Leviathan

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

MuddyWater

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

RedCurl

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Nomadic Octopus

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

APT42

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

HAFNIUM

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

UNC2726

Execution via WScript pulls a second-stage payload -- historically Cobalt Strike beacons, NetSupport RAT, or Python-based backdoors.

Earth Baxia

This exploit allowed the attackers to download or copy malicious components, which were then used to deploy customized Cobalt Strike payloads. Their modified Cobalt Strike version included altered signatures for evasion...

NilePhish

Cobalt Strike is a commercial penetration testing suite, that is sold for legitimate security audits of organizations. Since 2016, Cobalt Strike has been identified as being abused by many attack groups... An obfuscated VBS script located at https://files.browserupdate[.]download/a downloads a Cobalt Strike payload from the same server on port 443 and launches it.

Earth Lamia

China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors

UNC5174

China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors

Jackpot Panda

China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors

Earth Kurma

These consist of Cobalt Strike Beacons, rootkits like KRNRAT and Moriya, as well as data exfiltration malware.

SaintBear

Once the user opens the link two files are downloaded, one is Cobalt Strike Beacon...

ZIRCONIUM

...launching a Cobalt Strike loader dubbed CloudyLoader via DLL side-loading.

UNC5221

"Cobalt Strike is a commercial adversary simulation tool, long favored by both red teams and threat actors."

TA575

...TA575 criminal group is made up of prolific, financially-motivated opportunists who specialize in Dridex malware and operate swaths of Cobalt Strike servers.

UNC2447

"...offensive security tools such as Cobalt Strike, PowerSploit, Mimikatz, and Impacket..."

LAPSUS$

"...offensive security tools such as Cobalt Strike, PowerSploit, Mimikatz, and Impacket..."

RedNovember

...deploy Spark RAT and Cobalt Strike Beacons...

slow#tempest

"...targeting Chinese-speaking users with Cobalt Strike and Mimikatz payloads."

Mustard Tempest

"With Hades attacks, GOLD DRAKE made extensive use of Cobalt Strike..."

Yanluowang

"...offensive security tools such as Cobalt Strike, PowerSploit, Mimikatz, and Impacket..."

Black Basta

The file installed Qakbot and Cobalt Strike on the compromised device and then deployed ransomware.

APT-Q-20

...deployed remote access tools such as Cobalt Strike or Sliver for remote and persistent access.

CTG-5938

Third party reporting also suggests that the group has adopted tools including the ANEL backdoor and Cobalt Strike.

PoisonVine

...deployed remote access tools such as Cobalt Strike or Sliver for remote and persistent access.

Storm-0506

"The threat actor then used Cobalt Strike and Pypykatz..."

APT-C-01

...deployed remote access tools such as Cobalt Strike or Sliver for remote and persistent access.

Team46

...often using loaders like Donut or Cobalt Strike.

GreenSpot

...deployed remote access tools such as Cobalt Strike or Sliver for remote and persistent access.

Ryuk

"...the Buer Loader malware dropped qoipozincyusury.exe, a Cobalt Strike 'beacon'..."

Chamelgang

"...used to sign Cobalt Strike and BYOVD-related malware uploaded to VirusTotal."

FIN11

Ultimately, Microsoft says a Cobalt Strike beacon was deployed and used to spread laterally through the network while stealing data...

UAT-8099

"In addition, Cobalt Strike is deployed as the preferred backdoor for post-exploitation."

BlackByte

APT32 malware has injected a Cobalt Strike beacon into Rundll32.exe.

TA551

"...potentially broker access to enable the deployment of Cobalt Strike and eventually ransomware."

camofei

"...used to sign Cobalt Strike and BYOVD-related malware uploaded to VirusTotal."

Cardinal

“…attempts to sell hacking tools, such as a modified version of Cobalt Strike.”

Gold Dupont

With the final payload in place, the attacker was able to load and execute the Cobalt Strike payload, allowing it to communicate with the command and control (C&C) server.

TAC5279

"Employing tools such as SystemBC, PortStarter, and occasionally Cobalt Strike"

REF9019

Cobalt Strike was used in these intrusions... dhl.jpg ... and temp.png ... are being used for command and control.

Velvet Ant

This behavior is unusual and often associated with malicious activities, such as those performed by Cobalt Strike.

SparklingGoblin

...SparklingGoblin also used a Cloudflare worker domain with Cobalt Strike: cdn.cloudfiare.workers[.]dev.

PLATINUM

its execution without them, especially with network activity, is often associated with malicious software like Cobalt Strike.

UNK_FistBump

Earlier UNK_FistBump campaigns delivered a Cobalt Strike Beacon payload... decrypts the RC4-encrypted Cobalt Strike Beacon payload from the rc4.log file... communicates with the Evoxt VPS C2 IP address 166.88.61[.]35 over port TCP 443.

TianWu

After gaining access, the operators deployed SnakeC2, NEOBEACON (which abuses OneDrive and the Microsoft Graph API for C2), Cobalt Strike, VShell, and SoftEther VPN.

APT37

its execution without them, especially with network activity, is often associated with malicious software like Cobalt Strike.

Play

By abusing legitimate tools such as Cobalt Strike, Mimikatz, ProcDump, AdFind, and WinPEAS, the group conducts credential theft, privilege escalation, lateral movement, and data exfiltration.

UAT-10027

"The payload is assessed to be a Cobalt Strike Beacon."

TA584

"TA584 has a history of using various payloads, including Ursnif and Cobalt Strike."

Lunar Spider

"...using web shells, open-source hacking tools, Cobalt Strike, and various BadIIS malware..." and "...including Latrodectus, Brute Ratel C4, Cobalt Strike, BackConnect..."

UNC2465

The execution of ScareCrow framework dropper... resulted in the creation of a Cobalt Strike stageless payload... which then established a connection to a Cobalt Strike Beacon server located at w2doger[.]xyz

RomCom

"...including NetSupport, Cobalt Strike BEACON..." / "...frequently using BEACON to facilitate this movement."

TGR-STA-1030

...download three images ... which serve as a conduit for the deployment of a Cobalt Strike payload.

Sylvanite

"The group also used tooling such as Cobalt Strike, Sliver, and multiple web shells, then handed access to other actors, including VOLTZITE."

APT17

Researchers at Check Point said the group has been active since mid-2024... deploy Cobalt Strike beacons for remote access.

Silver Dragon

Researchers at Check Point said the group has been active since mid-2024... deploy Cobalt Strike beacons for remote access.

SloppyLemming

This evolution includes the use of the Rust programming language, a departure from previous reliance on traditional compiled languages and frameworks like Cobalt Strike and Havoc.

Fishing Elephant

"...borrowed adversary simulation frameworks such as Cobalt Strike, Havoc..."

Outrider Tiger

"...borrowed adversary simulation frameworks such as Cobalt Strike, Havoc..."

Exploited software

Vulnerabilities linked to Cobalt Strike

83 CVEs
CVE-2026-54121 Certighost CVE-2021-34527 PrintNightmare CVE-2021-22941 Unauthenticated Path Traversal RCE in Citrix ShareFile Storage Zones Controller CVE-2023-23752 Improper Access Control in Joomla! Webservice Endpoints CVE-2022-27925 Directory Traversal in Zimbra Collaboration Suite mboximport CVE-2021-27076 Replay-based RCE in Microsoft SharePoint Server CVE-2024-36401 Unauthenticated RCE in GeoServer via XPath Expression Evaluation CVE-2024-23897 Jenkins CLI Arbitrary File Read CVE-2022-41082 ProxyNotShell RCE in Microsoft Exchange Server PowerShell CVE-2025-55182 React2Shell CVE-2022-40684 Authentication Bypass in Fortinet FortiOS, FortiProxy, and FortiSwitchManager Administrative Interface CVE-2023-32315 Openfire Admin Console Authentication Bypass via Path Traversal CVE-2023-46747 F5 BIG-IP TMUI Authentication Bypass Leading to RCE CVE-2021-36260 Unauthenticated Command Injection in Hikvision Web Server CVE-2021-26855 ProxyLogon SSRF in Microsoft Exchange Server CVE-2016-4437 Apache Shiro rememberMe deserialization RCE / auth bypass CVE-2024-21762 Fortinet FortiOS/FortiProxy SSL-VPN Out-of-Bounds Write RCE CVE-2023-20198 Authentication Bypass in Cisco IOS XE Web UI CVE-2024-27198 Authentication Bypass in JetBrains TeamCity On-Premises CVE-2021-40444 Microsoft MSHTML Remote Code Execution Vulnerability CVE-2022-30190 Follina MSDT Remote Code Execution CVE-2019-18935 Remote Code Execution in Progress Telerik UI for ASP.NET AJAX RadAsyncUpload CVE-2019-9621 SSRF in Zimbra Collaboration Suite ProxyServlet CVE-2021-22205 GitLab CE/EE ExifTool Image Parsing Remote Code Execution CVE-2021-34473 ProxyShell Autodiscover SSRF/Auth Bypass in Microsoft Exchange Server CVE-2019-9670 XXE in Synacor Zimbra Collaboration Suite mailboxd Autodiscover CVE-2022-39952 Unauthenticated RCE in Fortinet FortiNAC CVE-2025-31324 Unauthenticated Arbitrary File Upload RCE in SAP NetWeaver Visual Composer Metadata Uploader CVE-2017-8759 .NET Framework WSDL Parsing Remote Code Execution CVE-2025-30406 Gladinet CentreStack/Triofox ASP.NET ViewState Deserialization RCE CVE-2025-0994 Remote Code Execution in Trimble Cityworks Deserialization CVE-2021-34523 Microsoft Exchange PowerShell Backend Elevation of Privilege (ProxyShell) CVE-2017-0199 Microsoft Office/WordPad OLE2Link Remote Code Execution CVE-2021-31207 Post-auth Arbitrary File Write in Microsoft Exchange Server (ProxyShell) CVE-2025-0944 SQL Injection in itsourcecode Tailoring Management System 1.0 customerview.php CVE-2026-5426 Unauthenticated ViewState Deserialization RCE in Digital Knowledge KnowledgeDeliver CVE-2020-1472 ZeroLogon CVE-2024-57727 Unauthenticated Path Traversal in SimpleHelp CVE-2023-38831 WinRAR Archive Name Confusion Arbitrary Code Execution CVE-2025-7775 Citrix NetScaler ADC/Gateway Memory Overflow RCE CVE-2022-21587 Unauthenticated Arbitrary File Upload RCE in Oracle Web Applications Desktop Integrator CVE-2022-47986 RCE in IBM Aspera Faspex via YAML Deserialization CVE-2023-27350 PaperCut MF/NG Authentication Bypass and RCE CVE-2021-44228 Log4Shell CVE-2021-35211 Remote Code Execution in SolarWinds Serv-U via SSH CVE-2024-12802 MFA Bypass in SonicWall SSL-VPN Active Directory Authentication CVE-2017-0144 EternalBlue SMBv1 Remote Code Execution Vulnerability CVE-2018-13379 Fortinet FortiOS SSL VPN Path Traversal Credential Exposure CVE-2021-31206 Remote Code Execution in Microsoft Exchange Server CVE-2021-21985 RCE in VMware vCenter Server vSphere Client VSAN Health Check Plug-in CVE-2017-15944 Remote Code Execution in Palo Alto Networks PAN-OS Management Interface CVE-2018-1207 Unauthenticated CGI Injection RCE in Dell EMC iDRAC7/iDRAC8 CVE-2021-26857 Microsoft Exchange Unified Messaging insecure deserialization RCE CVE-2021-31196 Microsoft Exchange Server Remote Code Execution Vulnerability CVE-2021-31195 ProxyOracle Reflected XSS in Microsoft Exchange Server CVE-2021-27065 Arbitrary File Write in Microsoft Exchange Server ECP CVE-2022-41080 OWASSRF in Microsoft Exchange Server CVE-2022-41040 ProxyNotShell SSRF in Microsoft Exchange Server CVE-2019-16098 Arbitrary kernel memory access in MSI Afterburner RTCore64.sys/RTCore32.sys CVE-2026-21509 Microsoft Office OLE Security Feature Bypass CVE-2025-15556 Notepad++ WinGUp updater download of code without integrity check CVE-2017-11882 Microsoft Equation Editor Stack Buffer Overflow RCE CVE-2020-10189 Unauthenticated RCE in Zoho ManageEngine Desktop Central getChartImage CVE-2019-19781 Citrix ADC and Gateway Directory Traversal Leading to Unauthenticated RCE CVE-2021-26858 Post-authentication arbitrary file write in Microsoft Exchange Server CVE-2013-2465 Oracle Java 2D incorrect image channel verification sandbox bypass / RCE CVE-2011-3544 Oracle Java Rhino Script Engine Remote Code Execution CVE-2013-2460 Oracle Java Serviceability sandbox bypass in Java 7u21 and earlier CVE-2012-4681 Oracle Java 7 SecurityManager Sandbox Bypass Remote Code Execution CVE-2023-27351 Authentication Bypass in PaperCut NG/MF SecurityRequestFilter CVE-2022-37042 Authentication Bypass in Zimbra Collaboration Suite MailboxImportServlet CVE-2022-30333 Directory Traversal in RARLAB UnRAR Extraction on Linux and UNIX CVE-2022-24682 Stored XSS in Zimbra Collaboration Suite Calendar CVE-2022-27924 Unauthenticated Memcache Command Injection in Zimbra Collaboration Suite CVE-2024-23692 Unauthenticated RCE in Rejetto HTTP File Server via Template Injection CVE-2024-30051 Windows DWM Core Library Elevation of Privilege Vulnerability CVE-2021-1879 Apple WebKit Universal Cross-Site Scripting in iOS, iPadOS, and watchOS CVE-2024-37085 Authentication Bypass in VMware ESXi Active Directory Integration CVE-2024-4577 PHP-CGI Argument Injection RCE on Windows CVE-2023-47246 Path Traversal RCE in SysAid On-Premise CVE-2025-22457 Remote Code Execution in Ivanti Connect Secure, Policy Secure, and ZTA Gateways CVE-2020-16040 Insufficient data validation in Google Chrome V8 CVE-2025-0282 Unauthenticated RCE in Ivanti Connect Secure, Policy Secure, and Neurons for ZTA Gateway

MITRE ATT&CK

Cobalt Strike in ATT&CK

126 distinct techniques

Techniques

126 techniques
T1071 Application Layer Protocol T1105 Ingress Tool Transfer T1562.001 Disable or Modify Tools T1190 Exploit Public-Facing Application T1041 Exfiltration Over C2 Channel T1106 Native API T1548.002 Bypass User Account Control T1140 Deobfuscate/Decode Files or Information T1033 System Owner/User Discovery T1566.001 Spearphishing Attachment T1204.001 Malicious Link T1071.001 Web Protocols T1055 Process Injection T1573.001 Symmetric Cryptography T1027.010 Command Obfuscation T1059.001 PowerShell T1059 Command and Scripting Interpreter T1082 System Information Discovery T1135 Network Share Discovery T1046 Network Service Discovery T1021 Remote Services T1570 Lateral Tool Transfer T1090.003 Multi-hop Proxy T1583.003 Virtual Private Server T1583.006 Web Services T1021.002 SMB/Windows Admin Shares T1482 Domain Trust Discovery T1559.001 Component Object Model T1069 Permission Groups Discovery T1573 Encrypted Channel T1543.003 Windows Service T1550.002 Pass the Hash T1078 Valid Accounts T1053 Scheduled Task/Job T1018 Remote System Discovery T1003.001 LSASS Memory T1620 Reflective Code Loading T1219 Remote Access Tools T1596.005 Scan Databases T1596.003 Digital Certificates T1505.003 Web Shell T1203 Exploitation for Client Execution T1012 Query Registry T1547.001 Registry Run Keys / Startup Folder T1562 Impair Defenses T1112 Modify Registry T1595 Active Scanning T1590 Gather Victim Network Information T1055.012 Process Hollowing T1566.002 Spearphishing Link T1027 Obfuscated Files or Information T1016 System Network Configuration Discovery T1055.001 Dynamic-link Library Injection T1584.001 Domains T1003.003 NTDS T1001.003 Protocol or Service Impersonation T1003 OS Credential Dumping T1053.005 Scheduled Task T1036 Masquerading T1574.001 DLL T1027.006 HTML Smuggling T1090 Proxy T1059.005 Visual Basic T1195 Supply Chain Compromise T1588.002 Tool T1195.002 Compromise Software Supply Chain T1078.002 Domain Accounts T1059.003 Windows Command Shell T1070.004 File Deletion T1569 System Services T1566 Phishing T1134.004 Parent PID Spoofing T1083 File and Directory Discovery T1497 Virtualization/Sandbox Evasion T1087 Account Discovery T1057 Process Discovery T1072 Software Deployment Tools T1583.001 Domains T1610 Deploy Container T1027.007 Dynamic API Resolution T1090.004 Domain Fronting T1134.001 Token Impersonation/Theft T1069.002 Domain Groups T1588.001 Malware T1030 Data Transfer Size Limits T1087.002 Domain Account T1565 Data Manipulation T1218 System Binary Proxy Execution T1027.002 Software Packing T1583 Acquire Infrastructure T1574 Hijack Execution Flow T1189 Drive-by Compromise T1218.011 Rundll32 T1036.005 Match Legitimate Resource Name or Location T1649 Steal or Forge Authentication Certificates T1608.006 SEO Poisoning T1071.004 DNS T1204.002 Malicious File T1113 Screen Capture T1056.001 Keylogging T1204 User Execution T1572 Protocol Tunneling T1090.002 External Proxy T1665 Hide Infrastructure T1115 Clipboard Data T1558 Steal or Forge Kerberos Tickets T1558.003 Kerberoasting T1505 Server Software Component T1608.001 Upload Malware T1499 Endpoint Denial of Service T1584.004 Server T1129 Shared Modules T1059.010 AutoHotKey & AutoIT T1560 Archive Collected Data T1048 Exfiltration Over Alternative Protocol T1553.002 Code Signing T1059.004 Unix Shell T1569.002 Service Execution T1132 Data Encoding T1218.010 Regsvr32 T1005 Data from Local System T1070.006 Timestomp T1559 Inter-Process Communication T1070 Indicator Removal T1068 Exploitation for Privilege Escalation T1059.007 JavaScript

Reporting

Research mentioning Cobalt Strike

Aug 3
Malware News

Cyber Conflict Briefing Q2 2026 - Malware Analysis - Malware Analysis, News and Indicators

The Qilin ransomware group claimed multiple new victims across the United States, Canada, Austria, and Germany, hitting organizations in manufacturing, professional services, financial services, media, retail, property management, and utilities. Named victims included Community Management Associates, Pointe Property Group, Ceragres, Dienst Pack Systems, Schreiner Trockenbau GmbH, Commercial Furniture Interiors, The Saturday Evening Post, Wire Products, Freedom Claims Management, and Service Electric. Several reports described the incidents as both ransomware attacks and associated data breaches, indicating continued emphasis on extortion through stolen data as well as operational disruption. Separate reporting tied Qilin affiliates to active exploitation of Internet-facing VPN and firewall infrastructure, including Palo Alto GlobalProtect CVE-2026-0257 and Check Point VPN CVE-2026-50751, as part of broader mid-2026 ransomware access campaigns. That activity was reported alongside common post-compromise tradecraft such as Impacket, NTLM relay, Mimikatz, PsExec, RDP, WMI, browser credential theft, and use of WSL for EDR evasion. A weekly ransomware trend report counted Qilin among the most active groups, with 31 claimed victims during the period, reinforcing its position as a leading extortion threat affecting organizations across sectors and regions.

Aug 3
Cyberveille

Tendances ransomware - Semaine 31/2026 | CyberVeille

Aug 3
Hookphish

Ransomware Group qilin Hits: Service Electric

Aug 3
Securelist

Incident response statistics and cases at educational institutions in Brazil | Securelist

Brazilian educational institutions faced a sustained wave of cyber incidents in incident-response cases reviewed from January 2025 through June 2026, with attackers most often gaining access through valid accounts, exploitation of public-facing applications, insider activity, and weak patch management. High-severity cases were dominated by ransomware, particularly DragonForce and LockBit 3, and private institutions were more frequently affected than public ones. Investigators also found that outdated and unpatched systems, including Windows 10 deployments kept past end of support and unpatched Windows Server 2016 hosts, materially increased exposure. Representative intrusions showed attackers relying on common but effective techniques rather than novel tradecraft. One LockBit case involved a custom deployment built from the leaked builder and spread with PsExec, aligning with the well-documented abuse of Windows service execution for lateral movement and payload launch. Another DragonForce intrusion used AnyDesk and log wiping to maintain access and hinder response, while a separate insider case involved a Python keylogger installed on a shared machine to capture credentials. The findings underscore the need for MFA, least privilege, removal of shared accounts, tighter control of remote-access tools, stronger backups, centralized logging, longer EDR retention, and faster patching.

Aug 3
Hookphish

Ransomware Group qilin Hits: Freedom Claims Management

Aug 2
Hookphish

Ransomware Group shinyhunters Hits: Questel SAS

Aug 2
Hookphish

Ransomware Group qilin Hits: Wire Products

Aug 1
Cyberveille

Vague d'exploitation VPN : Palo Alto, Fortinet, Citrix et Check Point ciblés par des ransomwares | CyberVeille

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.