Skip to content

Cobalt Strike

Cobalt Strike is a commercial adversary-emulation and penetration-testing framework frequently abused in intrusions.

Profile source: Mallory opens in a new tab

Cobalt Strike

Family profile

Cobalt Strike is a commercial adversary-emulation and penetration-testing framework frequently abused in intrusions. Its primary endpoint implant, Beacon, is an in-memory post-exploitation backdoor that can be reflectively loaded into processes and configured with malleable command-and-control profiles. Beacon supports command execution, host and user discovery, file transfer, keylogging, SOCKS proxying, port scanning, credential-access functions including Mimikatz integration, privilege escalation, process injection, and lateral movement. It supports command-and-control and staging through HTTP, HTTPS, DNS, SMB named pipes, and forward or reverse TCP, and Beacons can be chained through peer-to-peer communications. Cobalt Strike is broadly used by ransomware operators, financially motivated criminal groups, and espionage actors, including reported use by Conti, Warlock, and APT36-associated activity. It is commonly deployed as a secondary payload after initial compromise rather than serving as an initial-access mechanism itself. Cobalt Strike Beacon primarily targets Windows systems.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Lateral Movement
  • Post Exploitation
  • Privilege Escalation
  • Process Injection
  • Reconnaissance
  • Scanning

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 22, 2026
Last activity
Aug 29, 2026
Feed role
C2 / Distribution
Host form
206 IP / 97 hostnames

Leading locations

  • CN83
  • US64
  • HK27
  • DE25
  • NL17
  • RU10
  • KR9
  • LU5
  • SG5
  • FR4
  • PL4
  • BR3

Leading providers

  • Shenzhen Tencent Computer Systems Company Limited27
  • Hangzhou Alibaba Advertising Co.,Ltd.22
  • Amazon.com, Inc.16
  • Cloudflare, Inc.11
  • CHINA UNICOM China169 Backbone9
  • China Telecom Beijing Tianjin Hebei Big Data Industry Park Branch8

Infrastructure traits

  • Hosting 232
  • Anycast 14
  • Vpn 1

Samples

Recent associated samples

Reported operators

Threat actors

195 named in public reporting
Transparent Tribe

GOSHELL описан как loader для Cobalt Strike Beacon с HTTP/S C2.

Water Manaul

The compromised SharePoint worker process w3wp.exe spawned a Cobalt Strike beacon through DLL sideloading using MsMpSrv.exe and a malicious MsEdge.dll.

Leviathan

Cobalt Strike is a penetration testing tool that allows an attacker to deploy an agent named ‘Beacon’ on the target machine.

TA505

after which they deployed a Cobalt Strike beacon, carried out additional reconnaissance and lateral movement, and finally identified and exfiltrated the target organization’s files.

APT29

SNOWYAMBER first appeared in October 2022. It is a dropper ... and deploys Cobalt Strike and BruteRatel ... as second-stage payloads.

Tropic Trooper

このPEファイルの実体はCobalt Strike Beaconでした。Cobalt Strikeは、正規のソフトウェアでありながら、その充実した機能から、不正規なライセンスにより攻撃者に悪用されている遠隔操作ソフトウェアです。

Qakbot

Many of the malware families were some bigger name malware such as: Zloader, IcedID, CobaltStrike (multiple actors, including Qakbot), NetSupportRAT, RemcosRAT, BazaarLoader

Cobalt Group

In their previous spear-phishing campaigns, the DLL is a component of the penetration testing tool Cobalt Strike, which they abuse to hijack the infected system.

TA578

2022-06-28 (TUESDAY) - TA578 ICEDID (BOKBOT) WITH BACKCONNECT, ANUBIS VNC AND COBALT STRIKE

Chimera

Chimera has used scheduled tasks to invoke Cobalt Strike... and to maintain persistence.

WIZARD SPIDER

"URL": "https://www.cobaltstrike.com/help-authorization-files" ... entries map authorization values to labels associated with malware and threat actors.

APT41

"URL": "https://www.cobaltstrike.com/help-authorization-files" ... entries map authorization values to labels associated with malware and threat actors.

Threat Group-3390

"URL": "https://www.cobaltstrike.com/help-authorization-files" ... entries map authorization values to labels associated with malware and threat actors.

TA511

"URL": "https://www.cobaltstrike.com/help-authorization-files" ... entries map authorization values to labels associated with malware and threat actors.

CopyKittens

CopyKittens uses rundll32 to load various tools on victims, including a lateral movement tool named Vminst, Cobalt Strike, and shellcode.

Storm-1811

Cinnamon Tempest has used search order hijacking to launch Cobalt Strike Beacons. Storm-1811 ... sideloaded ... to load a Cobalt Strike beacon payload.

Storm-0501

Storm-0501 has launched Cobalt Strike Beacon files using regsvr32.exe.

APT32

APT32 has also renamed a Cobalt Strike beacon payload to install_flashplayers.exe.

UAC-0098

Зазначене призведе до ураження комп'ютера шкідливою програмою Cobalt Strike Beacon... notevil.dll (CS Beacon)

Cinnamon Tempest

Cinnamon Tempest has used search order hijacking to launch Cobalt Strike Beacons. Storm-1811 ... sideloaded ... to load a Cobalt Strike beacon payload.

Mustang Panda

APT32 has also renamed a Cobalt Strike beacon payload to install_flashplayers.exe.

DarkCasino

The New APT Group DarkCasino and the Global Surge in WinRAR 0-Day Exploits Cobalt Strike Konni

BRONZE EDGEWOOD

BRONZE ATLAS ... Tools ... Acehash, CCleaner v5.33 backdoor, ChinaChopper, Cobalt Strike, Dicey MSDN, Dodgebox, DUSTPAN, ForkPlayground, HUC Proxy Malware (Htran)

INDRIK SPIDER

Similarly, a customized version of the CobaltStrike loader has been observed, possibly intended as a replacement for the Empire PowerShell framework previously used.

APT6

The first HTTP request to that domain is used to download a 261703 byte file... This turns out to be a Cobalt Strike beacon download... The output from 1768.py reveals that this Cobalt Strike beacon is using the following URIs for C2 communication.

UNC2447

Threat actors need only deliver Cobalt Strike’s Beacon – a highly configurable backdoor that allows attackers to quietly and remotely control endpoints and inject other attacker tools – as a payload of their chosen initial access vector.

TA800

a public malware sandbox run seems to show it receiving a “powershell” command that ultimately delivered a Cobalt Strike beacon... There has been some evidence suggesting NimzaLoader is being used to download and execute Cobalt Strike as its secondary payload

TA577

Threat actors need only deliver Cobalt Strike’s Beacon – a highly configurable backdoor that allows attackers to quietly and remotely control endpoints and inject other attacker tools – as a payload of their chosen initial access vector.

Conti

In almost all cases, the initial access brokers such as Trickbot and Bazar, dropped multiple Cobalt Strike beacons across the victim environment.

FIN6

Threat actor used mostly Cobalt Strike and phishing emails and documents on behalf of Slovak National Security Authority... This DLL file is actually a Cobalt Strike Beacon.

UNC1151

UAC-0051 aka unc1151 (Cobalt Strike Beacon, MicroBackdoor)

APT19

Threat actor used mostly Cobalt Strike and phishing emails and documents on behalf of Slovak National Security Authority... This DLL file is actually a Cobalt Strike Beacon.

TA551

Threat actors need only deliver Cobalt Strike’s Beacon – a highly configurable backdoor that allows attackers to quietly and remotely control endpoints and inject other attacker tools – as a payload of their chosen initial access vector.

Trickbot

Similar to the majority of Baza campaigns, the tasks that were executed came in the form of cobalt strike stagers.

GOLD LAGOON

Secureworks CTU researchers conducted a focused investigation into malicious use of Cobalt Strike... Qakbot profiled the infected host, sent the profiled data to its C2 servers, and then downloaded and executed Cobalt Strike Beacon.

The Conti Group

Some important things to track on the back of this leak to help defend your network. Cobalt Strike servers.

UAC-0051

UAC-0051 aka unc1151 (Cobalt Strike Beacon, MicroBackdoor)

SparklingGoblin

It makes use of Motnug and ChaCha20-based loaders, the CROSSWALK and SideWalk backdoors, along with Korplug (aka PlugX) and Cobalt Strike.

OldGremlin

Like many other groups, OldGremlin used the Cobalt Strike framework to ensure that any post-exploitation activity was as effective as possible.

SideWinder

The newly discovered WarHawk backdoor contains various malicious modules that deliver Cobalt Strike... WarHawk is commissioned to deliver Cobalt Strike as the final payload.

Salt Typhoon

TeleBoyi’s Arsenal ◆Malware ◆... ◆CobaltStrike ◆Sliver ◆AsyncRAT

EXOTIC LILY

Approximately 14 minutes after HTTPS traffic to the amazonAWS server, HTTPS Cobalt Strike traffic appeared on 23.106.215[.]123 over TCP port 443 using xenilik[.]com as the domain.

Black Basta

In this threat alert, the Cybereason team describes one attack scenario that started from a QBot infection, resulting in multiple key machines loading Cobalt Strike, which finally led to the global deployment of Black Basta ransomware.

Lazarus

The newly discovered WarHawk backdoor contains various malicious modules that deliver Cobalt Strike... WarHawk is commissioned to deliver Cobalt Strike as the final payload.

menuPass

It was identified that this payload was a PlugX variant or a CobaltStrike Beacon as a post-exploitation framework.

Ember Bear

...наступний PowerShell-скрипт, який, у свою чергу, забезпечить виконання шкідливої програми Cobalt Strike Beacon.

MuddyWater

Running HR-Update.exe was a Cobalt Strike beacon. Cobalt Strike, a penetration testing tool, can also be used by attackers for gaining a foothold in the system. The final ransomware payload is downloaded with the help of Cobalt Strike.

hydrochasma

Cobalt Strike Beacon : An off-the-shelf tool that can be used to execute commands, inject other processes, elevate current processes, or impersonate other processes, and upload and download files.

A41APT

SigLoader and SodaMaster are still used in 2021 ○ Cobalt Strike, P8RAT and FYAntiLoader were not observed in 2021

Harvester

Cobalt Strike Beacon - uses CloudFront infrastructure for its C&C activity (Cobalt Strike is an off-the-shelf tool that can be used to execute commands, inject other processes, elevate current processes, or impersonate other processes, and upload and download files)

UNC4696

This technique is commonly used by multiple intrusion sets to distribute... post-exploitation frameworks ( e.g. CobaltStrike, Sliver)...

EmpireMonkey

on the 6 th of February we identified an extremely high number of prevention events stopping Cobalt Strike backdoor execution... downloaded and reflectively loaded Cobalt-Strike beacon with PowerShell extension directly into the memory.

Rancor

During the months of May and June, Rancor continued to introduce new infection chains... In one case, the attackers turned to Cobalt Strike Beacon as their second stage payload.

SharpPanda

the campaign adopts Cobalt Strike Beacon as the payload, enabling backdoor functionalities like C2 communication and command execution

Snatch

What we refer to as Snatch malware comprises a collection of tooling, which include a ransomware component and a separate data stealer... a Cobalt Strike reverse-shell...

PassCV

2018年4月下旬頃からmenuPass(APT10) が、多機能なペネトレーションテストツール Cobalt Strike を悪用した攻撃を行っていることが複数確認できました。

Sharp Dragon

the campaign adopts Cobalt Strike Beacon as the payload, enabling backdoor functionalities like C2 communication and command execution

Water Minyades

If the victim host belongs to an enterprise environment, it is more likely to drop remote management tool Atera and Cobalt Strike beacon, which would then lead to ransomware deployment.

UNC1778

In our context, Trickbot uses the highjacked wermgr.exe process to load a Cobalt Strike beacon into memory.

PyXie

This loader has evolved as this threat group has taken advantage of multiple open source tools by altering the original application to execute payloads such as PyXie and/or Cobalt Strike.

SaintBear

In March, Cert-UA reported the group targeting state organizations in Ukraine using malicious implants called GrimPlant, GraphSteel and Cobalt Strike Beacon.

BRONZE BUTLER

Casper is a modified version of the Cobalt Strike backdoor, showing the team server SHA1 hash if the controller connects to the C&C.

ZIRCONIUM

APT31 ... Examples of associated tools: Cobalt Strike, DopboxAES Rat, SalsaTrade, PakDoor ... ; Mustang Panda ... Examples of associated tools: Cobalt Strike, PlugX...

REvil

Use of Cobalt Strike BEACON malware... Installation of commercial/freemium internet remote desktop software • Cobalt Strike BEACON... Cobalt Strike Module: Loaded using one of two methods.

DarkSide

Further analysis of an SMB beacon used by DarkSide reveals Cobalt Strike PowerShell code.

RomCom

The planted backdoors include Cobalt Strike or the NetSupport Manager remote access tool, but the group also uses their own ‘Bughatch’, ‘Wedgecut’, and ‘eck.exe”, and Burntcigar’ tools.

Gold Dupont

This loader has evolved as this threat group has taken advantage of multiple open source tools by altering the original application to execute payloads such as PyXie and/or Cobalt Strike.

ConfCrew

These checks then determine which malware will be installed, if all the conditions are met and the script is likely inside an enterprise then for this instance it will install CobaltStrike and AteraAgent RAT... CobaltStrike was also found to be leveraged by this actor for enterprise environments.

x4k

The discovered samples are primarily Cobalt Strike Beacons, utilizing heavy control flow obfuscation – unlike the HelloXD ransomware samples we had previously seen.

Dalbit

실제 명령 및 제어 단계에서 사용하는 악성코드들도 CobaltStrike, Metasploit, Ladaon, BlueShell 등 모두 외부에 공개되어 있는 도구들이다.

SilverFish

The initial backdoor was used five minutes later to deploy the second stage tool: Cobalt Strike.

FIN7

On the 2nd of January 2019 Cobalt Strike version 3.13 was released, which contained a fix for an “extraneous space”. This uncommon whitespace in its server responses represents one of the characteristics Fox-IT has been leveraging to identify Cobalt Strike Servers.

Overdose

Their most common attack chain largely begins via EMOTET malspam campaigns, which then loads TrickBot and/or other loaders, and moves to attack tools like PowerShell Empire or Cobalt Strike to accomplish objectives relative to the victim organization under attack.

Greenbug

The first activity was seen on October 11, 2019, when a malicious PowerShell command was executed to install a CobaltStrike Beacon module to download the next stage payload.

ShadowSyndicate

In the figure above one can see an overlap with known entities in our Opencti database with the offensive framework Cobalt strike.

Budworm

The group then abused the CyberArk Viewfinity software for DLL sideloading to load their custom HyperBro backdoor ... and used tools including Cobalt Strike.

Dark Peony

Majority of the sightings were for Cobalt Strike C2 framework spanning across different Cobalt Strike Watermarks.

SLIME88

SLIME88 has targeted Taiwan’s energy sector through phishing emails and fake certificate installer, attempting to deploy backdoor programs such as AdaptixC2 and CobaltStrike.

targetcompany

Phase 3 — Exécution du Cobalt Strike Beacon (C2) ... Injection en mémoire d’un Cobalt Strike Beacon

Earth Lusca

Its toolkit already spanned ShadowPad, Cobalt Strike and the Biopass RAT...

RedFoxtrot

RedFoxtrot utilise plusieurs méthodes et outils avec DcRat, notamment Cobalt Strike et AsyncRAT, pour l'infiltration et les activités de commande et de contrôle.

INC

A distinctive characteristic of INC Ransom’s operations is its extensive use of Living-off-the-Land Binaries (LOLBins), Remote Monitoring and Management (RMM) tools, post-exploitation frameworks such as Cobalt Strike, and custom scripts designed to automate ransomware propagation.

StrikeShark

The tool has been spotted delivering Cobalt Strike Beacon, a well known post exploitation framework, onto compromised machines.

Lotus Blossom

Beyond the custom backdoor, the Rapid7 researchers observed the deployment of Cobalt Strike and Metasploit frameworks, noting that the campaign was characterized by highly surgical targeting of government, telecommunications, and financial sectors rather than a broad, indiscriminate infection of the general user base.

DragonForce

they executed a PowerShell command to download additional payloads from a remote location using a Cobalt Strike Beacon, maintaining persistence throughout this process using SystemBC.

TA866

In several cases, we observed the repeated deployment of Cobalt Strike beacons following successful compromise of organizational networks.

Twelve

In one of the group’s attacks, we discovered traces of the Cobalt Strike framework, which the attackers used to contact their C2 and distribute malicious payloads.

UNC4393

One consistently observed method for establishing and maintaining a foothold was DNS BEACON. According to Cobalt Strike documentation, DNS beacons and listeners can be customized using Malleable C2 profiles.

Daggerfly

TAG-112 compromised at least two Tibetan community websites ... This JavaScript prompted visitors to download a fake security certificate, which, when opened, deployed the Cobalt Strike payload.

UAT-6382

Talos has so far found two types of payloads deployed by TetraLoader on the infected endpoints: Cobalt Strike beacons.

TAG-112

TAG-112 compromised at least two Tibetan community websites ... This JavaScript prompted visitors to download a fake security certificate, which, when opened, deployed the Cobalt Strike payload.

TAG-102

TAG-112 compromised at least two Tibetan community websites ... This JavaScript prompted visitors to download a fake security certificate, which, when opened, deployed the Cobalt Strike payload.

Earth Krahang

Cobalt Strike was also frequently used during the initial stage of an attack. Interestingly, we found that instead of the typical Cobalt Strike usage, Earth Krahang adds additional protection to their C&C server through the adoption of the open-source project RedGuard.

Kimsuky

----[ 2.3 Private Cobalt Strike Beacon Drop Location: mnt/hgfs/Desktop/111/beacon This is a custom Cobalt Strike C2 Beacon.

DarkHydrus

APT29 has obtained and used a variety of tools including Mimikatz, SDelete, Tor, meek, and Cobalt Strike.

SVR

TEARDROP or RAINDROP backdoors would be deployed, which would install a customized Cobalt Strike beacon in the environment, enumerating the domain and allowing for the collection and exfiltration of information of value using hands-on-keyboard techniques.

Sandworm

APT29 has obtained and used a variety of tools including Mimikatz, SDelete, Tor, meek, and Cobalt Strike.

BlackCat

Several Cobalt Strike framework capabilities were utilized by the threat actor throughout the course of the attack, including RDP tunnelling for lateral movement, and process injection for the purposes of execution and evasion.

Velvet Tempest

This industrialization of the cybercrime economy has made it easier for attackers to use ready-made penetration testing and other tools to perform their attacks. Within this category ... attackers using off-the-shelf tools, such as Cobalt Strike...

DEV-0365

This industrialization of the cybercrime economy has made it easier for attackers to use ready-made penetration testing and other tools to perform their attacks. Within this category ... attackers using off-the-shelf tools, such as Cobalt Strike...

DEV-0216

This industrialization of the cybercrime economy has made it easier for attackers to use ready-made penetration testing and other tools to perform their attacks. Within this category ... attackers using off-the-shelf tools, such as Cobalt Strike...

DEV-0506

This industrialization of the cybercrime economy has made it easier for attackers to use ready-made penetration testing and other tools to perform their attacks. Within this category ... attackers using off-the-shelf tools, such as Cobalt Strike...

fin12

In nearly every single FIN12 intrusion since February 2020, FIN12 has used Cobalt Strike BEACON payloads to interact with victim networks, progressing through their attacks from internal reconnaissance to ransomware deployment.

UNG0002

Ultimately, the final stage drops a dangerous Cobalt Strike Beacon directly into memory . This implant establishes an outbound command-and-control connection to a remote server .

UNC3569

This is often followed by the deployment of Cobalt Strike BEACON on the compromised server to establish a foothold for further operations.

Vanilla Tempest

The weaponized tool used by Vice Society is Cobalt Strike, which allows the group to remotely access and control the infected endpoint.

Bl00Dy

The FBI also identified information relating to the download and execution of command and control (C2) malware such as DiceLoader, TrueBot, and Cobalt Strike Beacons, although it is unclear at which stage in the attack these tools were executed.

APT28

MITRE Software: Cobalt Strike.

Lockean

For lateral movement, the threat actor used the Cobalt Strike penetration testing framework, and the freely available Adfind, BloodHound, and BITSadmin tools.

DEV-0413

These attacks used the vulnerability, tracked as CVE-2021-40444, as part of an initial access campaign that distributed custom Cobalt Strike Beacon loaders.

PISTACHE TEMPEST

Les attaquants ont utilisé leur accès de bureau à distance afin d’exécuter deux portes dérobées : SystemBC et Cobalt Strike.

Storm-0390

Around three hours after execution of the initial IcedID malware, a cmd process was spawned from IcedID. This new process began beaconing to a Cobalt Strike server... Using the Cobalt Strike beacon, the threat actor looked up specific domain administrators... copied over a Cobalt Strike beacon to the domain controller and executed it.

Earth Longzhi

The malware used in the incident was a simple but custom Cobalt Strike loader. ... we discovered several custom loaders of Cobalt Strike, including similar samples uploaded in VirusTotal.

UAT-7237

SoundBill can be employed to decode and load any shellcode, including Cobalt Strike.

TEMP.Veles

Dragos has also observed entities associated with XENOTIME experimenting with the Cobalt Strike penetration testing framework.

UNC2628

Across all known intrusions, UNC2628 has made heavy use of the Cobalt Strike framework and BEACON payloads.

GroupCC

The malware used in the incident was a simple but custom Cobalt Strike loader. ... we discovered several custom loaders of Cobalt Strike, including similar samples uploaded in VirusTotal.

Storm-0257

CERT-UA said the malware gathers details including the computer name, operating system version, user account information, and running processes. The agency also warned that compromised systems could later receive a payload linked to the offensive hacking framework Cobalt Strike, a legitimate penetration-testing tool frequently abused by cybercriminals and state-backed groups.

FrostyNeighbor

Operators then manually decide whether to deliver a third-stage payload, typically a Cobalt Strike beacon, to high-value targets.

TA445

The name comes from the fact that it retrieves a Cobalt Strike beacon, from an attacker-controlled environment, disguised as a renderable image or hidden in a web-associated file type, like CSS, JS, or SVG.

PUSHCHA

The name comes from the fact that it retrieves a Cobalt Strike beacon, from an attacker-controlled environment, disguised as a renderable image or hidden in a web-associated file type, like CSS, JS, or SVG.

MirrorFace

MirrorFace has used tools including the Secure Copy Protocol (SCP) client from PuTTY and Cobalt Strike.

FIN10

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

TeamTNT

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

LazyScripter

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

TA2541

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Poseidon Group

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

UNC3886

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Blue Mockingbird

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

DarkVishnya

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

APT33

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Handala

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Gorgon Group

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Scattered Spider

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

ToddyCat

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

GALLIUM

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

MoustachedBouncer

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Stealth Falcon

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Molerats

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Gallmaker

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Medusa Group

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

TA459

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

APT38

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Gamaredon Group

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

FIN13

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

OilRig

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

HEXANE

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Tonto

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

FIN8

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Dragonfly

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

APT5

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

GOLD SOUTHFIELD

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Winter Vivern

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Volt Typhoon

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Turla

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

APT39

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

APT3

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Silence

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Confucius

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Inception

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

CURIUM

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Patchwork

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Fox Kitten

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

RedCurl

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

Nomadic Octopus

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

APT42

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

HAFNIUM

Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.

UNC2726

Execution via WScript pulls a second-stage payload -- historically Cobalt Strike beacons, NetSupport RAT, or Python-based backdoors.

Earth Baxia

This exploit allowed the attackers to download or copy malicious components, which were then used to deploy customized Cobalt Strike payloads. Their modified Cobalt Strike version included altered signatures for evasion...

NilePhish

Cobalt Strike is a commercial penetration testing suite, that is sold for legitimate security audits of organizations. Since 2016, Cobalt Strike has been identified as being abused by many attack groups... An obfuscated VBS script located at https://files.browserupdate[.]download/a downloads a Cobalt Strike payload from the same server on port 443 and launches it.

Earth Lamia

China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors

UNC5174

China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors

Jackpot Panda

China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors

Earth Kurma

These consist of Cobalt Strike Beacons, rootkits like KRNRAT and Moriya, as well as data exfiltration malware.

UNC5221

"Cobalt Strike is a commercial adversary simulation tool, long favored by both red teams and threat actors."

TA575

...TA575 criminal group is made up of prolific, financially-motivated opportunists who specialize in Dridex malware and operate swaths of Cobalt Strike servers.

LAPSUS$

"...offensive security tools such as Cobalt Strike, PowerSploit, Mimikatz, and Impacket..."

RedNovember

...deploy Spark RAT and Cobalt Strike Beacons...

slow#tempest

"...targeting Chinese-speaking users with Cobalt Strike and Mimikatz payloads."

Mustard Tempest

"With Hades attacks, GOLD DRAKE made extensive use of Cobalt Strike..."

Yanluowang

"...offensive security tools such as Cobalt Strike, PowerSploit, Mimikatz, and Impacket..."

APT-Q-20

...deployed remote access tools such as Cobalt Strike or Sliver for remote and persistent access.

CTG-5938

Third party reporting also suggests that the group has adopted tools including the ANEL backdoor and Cobalt Strike.

PoisonVine

...deployed remote access tools such as Cobalt Strike or Sliver for remote and persistent access.

Storm-0506

"The threat actor then used Cobalt Strike and Pypykatz..."

APT-C-01

...deployed remote access tools such as Cobalt Strike or Sliver for remote and persistent access.

Team46

...often using loaders like Donut or Cobalt Strike.

GreenSpot

...deployed remote access tools such as Cobalt Strike or Sliver for remote and persistent access.

Ryuk

"...the Buer Loader malware dropped qoipozincyusury.exe, a Cobalt Strike 'beacon'..."

Chamelgang

"...used to sign Cobalt Strike and BYOVD-related malware uploaded to VirusTotal."

FIN11

Ultimately, Microsoft says a Cobalt Strike beacon was deployed and used to spread laterally through the network while stealing data...

UAT-8099

"In addition, Cobalt Strike is deployed as the preferred backdoor for post-exploitation."

BlackByte

APT32 malware has injected a Cobalt Strike beacon into Rundll32.exe.

camofei

"...used to sign Cobalt Strike and BYOVD-related malware uploaded to VirusTotal."

Cardinal

“…attempts to sell hacking tools, such as a modified version of Cobalt Strike.”

Exploited software

Vulnerabilities linked to Cobalt Strike

105 CVEs
CVE-2022-31199 Netwrix Auditor User Activity Video Recording Insecure Deserialization RCE CVE-2023-27350 Unauthenticated Remote Code Execution in PaperCut MF/NG SetupCompleted CVE-2023-40044 WS_FTP Server Ad Hoc Transfer .NET Deserialization RCE CVE-2025-55182 React2Shell CVE-2021-34473 ProxyShell Pre-authentication ACL Bypass in Microsoft Exchange Server CVE-2021-26855 Microsoft Exchange Server Pre-Authentication SSRF (ProxyLogon) CVE-2017-11882 Microsoft Office Equation Editor Remote Code Execution Vulnerability CVE-2013-3900 Windows Authenticode Signature Verification RCE CVE-2020-1472 Zerologon CVE-2021-34523 Microsoft Exchange Server PowerShell Backend Elevation of Privilege CVE-2021-40444 MSHTML Remote Code Execution in Microsoft Office Documents CVE-2021-31207 Microsoft Exchange Server Mailbox Export Arbitrary File Write CVE-2020-14882 Oracle WebLogic Server Console Unauthenticated Remote Code Execution CVE-2021-45046 Apache Log4j Thread Context Lookup Denial of Service CVE-2021-44228 Log4Shell CVE-2020-14750 Oracle WebLogic Server Console path traversal patch bypass leading to unauthenticated RCE CVE-2022-30190 Follina CVE-2021-36798 DoS in Cobalt Strike Team Server 4.2/4.3 CVE-2023-0669 Pre-authentication RCE in Fortra GoAnywhere MFT License Response Servlet CVE-2017-8759 .NET Framework WSDL Parser Remote Code Execution CVE-2021-26427 RCE in Microsoft Exchange Server 2013/2016/2019 (CVE-2021-26427) CVE-2022-26923 Certifried CVE-2021-27065 Microsoft Exchange Server Post-Authentication Arbitrary File Write (ProxyLogon) CVE-2021-26858 Microsoft Exchange Server post-authentication arbitrary file write CVE-2021-26857 Microsoft Exchange Unified Messaging insecure deserialization RCE CVE-2021-36942 PetitPotam / Windows LSA Spoofing Vulnerability CVE-2017-12824 Arbitrary Code Execution in InPage InPage100 Stream Parsing CVE-2022-26809 Remote Code Execution in Windows RPC Runtime CVE-2010-2861 Directory Traversal in Adobe ColdFusion Administrator Console CVE-2021-34527 PrintNightmare CVE-2019-0604 Microsoft SharePoint Application Package Remote Code Execution CVE-2022-24500 Remote Code Execution in Windows SMB Client CVE-2019-19781 Shitrix: Citrix ADC and Gateway Directory Traversal CVE-2021-27857 Missing Authorization in FatPipe WARP/IPVPN/MPVPN Web Management Interface CVE-2009-3960 XXE in BlazeDS and Adobe LiveCycle/ColdFusion CVE-2022-26134 Atlassian Confluence OGNL Injection Remote Code Execution CVE-2015-0096 DLL Planting Remote Code Execution Vulnerability in Windows Shell Link handling CVE-2021-45105 Apache Log4j2 Uncontrolled Recursion Denial of Service CVE-2023-4966 Citrix Bleed CVE-2026-54121 Certighost CVE-2021-22941 Unauthenticated Path Traversal RCE in Citrix ShareFile Storage Zones Controller CVE-2023-23752 Unauthenticated Information Disclosure in Joomla! Webservice Endpoints CVE-2022-27925 Directory Traversal in Zimbra Collaboration mboximport ZIP Extraction CVE-2021-27076 Remote Code Execution in Microsoft SharePoint Server CVE-2024-36401 GeoServer GeoTools XPath Evaluation Remote Code Execution CVE-2024-23897 Jenkins CLI Arbitrary File Read CVE-2022-41082 ProxyNotShell RCE in Microsoft Exchange Server CVE-2022-40684 Authentication Bypass in Fortinet FortiOS, FortiProxy, and FortiSwitchManager Administrative Interface CVE-2023-32315 Openfire Admin Console Authentication Bypass via Path Traversal CVE-2023-46747 F5 BIG-IP TMUI Authentication Bypass Remote Code Execution CVE-2021-36260 Unauthenticated Command Injection in Hikvision Web Server CVE-2016-4437 Apache Shiro rememberMe deserialization RCE / auth bypass CVE-2024-21762 Fortinet FortiOS and FortiProxy SSL-VPN Out-of-Bounds Write RCE CVE-2023-20198 Cisco IOS XE Web UI Privilege Escalation CVE-2024-27198 Authentication Bypass in JetBrains TeamCity On-Premises CVE-2019-18935 Remote Code Execution in Progress Telerik UI for ASP.NET AJAX RadAsyncUpload CVE-2019-9621 SSRF in Zimbra Collaboration Suite ProxyServlet CVE-2021-22205 Unauthenticated Remote Command Execution in GitLab CE/EE via ExifTool CVE-2019-9670 XXE in Synacor Zimbra Collaboration Suite mailboxd Autodiscover CVE-2022-39952 Unauthenticated RCE in Fortinet FortiNAC CVE-2025-31324 Unauthenticated Arbitrary File Upload RCE in SAP NetWeaver Visual Composer Metadata Uploader CVE-2025-30406 Gladinet CentreStack and Triofox ASP.NET ViewState Deserialization RCE CVE-2025-0994 Remote Code Execution in Trimble Cityworks Deserialization CVE-2017-0199 Microsoft Office and WordPad RTF Remote Code Execution CVE-2025-0944 SQL Injection in itsourcecode Tailoring Management System 1.0 customerview.php CVE-2026-5426 Unauthenticated ViewState Deserialization RCE in Digital Knowledge KnowledgeDeliver CVE-2024-57727 Unauthenticated Path Traversal in SimpleHelp CVE-2023-38831 WinRAR Arbitrary Code Execution via Same-Name File and Folder in Archive CVE-2025-7775 Unauthenticated RCE in Citrix NetScaler ADC and NetScaler Gateway CVE-2022-21587 Unauthenticated Arbitrary File Upload RCE in Oracle Web Applications Desktop Integrator CVE-2022-47986 RCE in IBM Aspera Faspex obsolete API via YAML deserialization CVE-2021-35211 Pre-auth RCE in SolarWinds Serv-U SSH CVE-2024-12802 MFA Bypass in SonicWall SSL-VPN Active Directory Authentication CVE-2017-0144 EternalBlue SMBv1 Remote Code Execution in Microsoft Windows CVE-2018-13379 Fortinet FortiOS SSL VPN Pre-Authentication Path Traversal CVE-2021-31206 Remote Code Execution in Microsoft Exchange Server CVE-2021-21985 Remote Code Execution in VMware vCenter Server vSphere Client VSAN Health Check Plug-in CVE-2017-15944 Remote Code Execution in Palo Alto Networks PAN-OS Management Interface CVE-2018-1207 Unauthenticated CGI Injection RCE in Dell EMC iDRAC7/iDRAC8 CVE-2021-31196 Remote Code Execution in Microsoft Exchange Server CVE-2021-31195 ProxyOracle in Microsoft Exchange Server CVE-2022-41080 OWASSRF authenticated SSRF in Microsoft Exchange Server CVE-2022-41040 ProxyNotShell SSRF in Microsoft Exchange Server CVE-2019-16098 Arbitrary Kernel Memory Access in MSI Afterburner RTCore Driver CVE-2026-21509 Microsoft Office OLE Security Feature Bypass CVE-2025-15556 Notepad++ WinGUp Updater Download of Code Without Integrity Check CVE-2020-10189 Remote Code Execution in Zoho ManageEngine Desktop Central getChartImage CVE-2013-2465 Oracle Java 2D Image Channel Verification Sandbox Bypass CVE-2011-3544 Oracle Java Rhino Script Engine Remote Code Execution CVE-2013-2460 Oracle Java SE 7 Serviceability Sandbox Bypass CVE-2012-4681 Oracle Java 7 SecurityManager Sandbox Bypass Remote Code Execution CVE-2023-27351 PaperCut NG/MF SecurityRequestFilter Authentication Bypass CVE-2022-37042 Authentication Bypass in Zimbra Collaboration Suite MailboxImportServlet CVE-2022-30333 Directory Traversal in RARLAB UnRAR Extraction on Linux and UNIX CVE-2022-24682 Stored XSS in Zimbra Collaboration Suite Calendar CVE-2022-27924 Unauthenticated Memcache Command Injection in Zimbra Collaboration Suite CVE-2024-23692 Rejetto HTTP File Server Template Injection RCE CVE-2024-30051 Windows DWM Core Library Elevation of Privilege Vulnerability CVE-2021-1879 Universal XSS in Apple WebKit CVE-2024-37085 Authentication Bypass in VMware ESXi Active Directory Integration CVE-2024-4577 PHP-CGI Argument Injection RCE on Windows CVE-2023-47246 SysAid On-Prem Path Traversal Remote Code Execution CVE-2025-22457 Remote Code Execution in Ivanti Connect Secure, Policy Secure, and ZTA Gateways CVE-2020-16040 Insufficient data validation in Google Chrome V8 CVE-2025-0282 Pre-auth RCE in Ivanti Connect Secure, Policy Secure, and Neurons for ZTA Gateways

MITRE ATT&CK

Cobalt Strike in ATT&CK

118 distinct techniques

Techniques

118 techniques
T1129 Shared Modules T1027 Obfuscated Files or Information T1190 Exploit Public-Facing Application T1055.003 Thread Execution Hijacking T1055.004 Asynchronous Procedure Call T1071.001 Web Protocols T1055.001 Dynamic-link Library Injection T1573 Encrypted Channel T1055 Process Injection T1090.002 External Proxy T1001.003 Protocol or Service Impersonation T1583.006 Web Services T1090.003 Multi-hop Proxy T1583.003 Virtual Private Server T1090 Proxy T1620 Reflective Code Loading T1082 System Information Discovery T1033 System Owner/User Discovery T1562 Impair Defenses T1003 OS Credential Dumping T1071 Application Layer Protocol T1570 Lateral Tool Transfer T1046 Network Service Discovery T1497.001 System Checks T1622 Debugger Evasion T1083 File and Directory Discovery T1059 Command and Scripting Interpreter T1204.002 Malicious File T1059.001 PowerShell T1021.002 SMB/Windows Admin Shares T1218 System Binary Proxy Execution T1048 Exfiltration Over Alternative Protocol T1543 Create or Modify System Process T1204 User Execution T1219 Remote Access Tools T1189 Drive-by Compromise T1112 Modify Registry T1059.004 Unix Shell T1105 Ingress Tool Transfer T1203 Exploitation for Client Execution T1071.004 DNS T1068 Exploitation for Privilege Escalation T1537 Transfer Data to Cloud Account T1587.001 Malware T1036 Masquerading T1588.007 Artificial Intelligence T1518 Software Discovery T1059.003 Windows Command Shell T1574.014 AppDomainManager T1566.001 Spearphishing Attachment T1134 Access Token Manipulation T1059.005 Visual Basic T1106 Native API T1218.005 Mshta T1018 Remote System Discovery T1027.007 Dynamic API Resolution T1021 Remote Services T1553.002 Code Signing T1140 Deobfuscate/Decode Files or Information T1564.001 Hidden Files and Directories T1132 Data Encoding T1562.001 Disable or Modify Tools T1053.005 Scheduled Task T1132.001 Standard Encoding T1027.005 Indicator Removal from Tools T1113 Screen Capture T1056.001 Keylogging T1572 Protocol Tunneling T1095 Non-Application Layer Protocol T1588.001 Malware T1057 Process Discovery T1135 Network Share Discovery T1016 System Network Configuration Discovery T1133 External Remote Services T1041 Exfiltration Over C2 Channel T1078 Valid Accounts T1566 Phishing T1218.011 Rundll32 T1548.002 Bypass User Account Control T1055.012 Process Hollowing T1218.010 Regsvr32 T1546.012 Image File Execution Options Injection T1005 Data from Local System T1090.004 Domain Fronting T1559.001 Component Object Model T1552 Unsecured Credentials T1053 Scheduled Task/Job T1059.006 Python T1047 Windows Management Instrumentation T1027.002 Software Packing T1550.002 Pass the Hash T1590 Gather Victim Network Information T1547.009 Shortcut Modification T1482 Domain Trust Discovery T1497 Virtualization/Sandbox Evasion T1566.002 Spearphishing Link T1543.003 Windows Service T1087.002 Domain Account T1555 Credentials from Password Stores T1055.009 Proc Memory T1003.001 LSASS Memory T1560 Archive Collected Data T1087 Account Discovery T1040 Network Sniffing T1195 Supply Chain Compromise T1497.003 Time Based Checks T1001 Data Obfuscation T1569.002 Service Execution T1102 Web Service T1021.003 Distributed Component Object Model T1070 Indicator Removal T1518.001 Security Software Discovery T1547 Boot or Logon Autostart Execution T1568 Dynamic Resolution T1110 Brute Force T1573.001 Symmetric Cryptography T1569 System Services T1132.002 Non-Standard Encoding

Reporting

Research mentioning Cobalt Strike

Aug 25
Trendai Security

Behind the Great Wall: Void Arachne Targets Chinese-Speaking Users With the Winos 4.0 C&C Framework | TrendAI (US)

TrendAI reported that a newly identified threat actor, Void Arachne, is targeting Chinese-speaking users with trojanized Windows Installer packages masquerading as AI tools, Telegram Simplified Chinese language packs, Google Chrome, and VPN software including LetsVPN and QuickVPN. The campaign uses attacker-controlled websites, SEO poisoning, and Chinese-language Telegram channels to distribute the fake installers, exploiting demand for censorship-evasion tools and popular AI-driven applications such as nudifier, face-swapping, and voice-changing software. The MSI-based infection chain ultimately deploys the Winos 4.0 backdoor, giving the operators persistent access for command execution, surveillance, keylogging, and plugin-enabled follow-on activity. TrendAI said the malware establishes persistence through scheduled tasks and services, adds firewall rules and port forwarding, and communicates with command-and-control infrastructure associated with webcamcn[.]xyz. The activity aligns with the broader MITRE ATT&CK T1566.002 Spearphishing Link pattern in which malicious links and deceptive delivery pages are used to lure victims into downloading malware-bearing installers and follow-on payloads.

Aug 20
Splunk Research

Detection: Windows Phantom DLL Created on Disk | Splunk Security Content

NightmareEclipse released ShieldBreak, a proof-of-concept local privilege-escalation exploit claimed to bypass Microsoft’s fix for CVE-2026-50656 (RoguePlanet). The exploit allegedly abuses improper link resolution during Windows Defender remediation, combining Cloud Files placeholders, Object Manager symbolic-link swaps, CLFS path handling, an EICAR-triggered scan, and NTFS alternate data streams to redirect a Defender process running as SYSTEM and plant C:\Windows\System32\phoneinfo.dll. A fabricated Windows Error Reporting report and the QueueReporting scheduled task then cause wermgr.exe to load the malicious DLL; the included Warden.dll payload reportedly duplicates a SYSTEM token and opens a SYSTEM shell in the unprivileged user’s session. Splunk published attack data and multiple disabled-by-default analytics for the ShieldBreak chain, covering Defender activity on \globalroot\ object-manager paths (Defender Operational events 1116/1117), MpClient.dll loaded by non-Defender processes, ADS creation through loopback administrative SMB shares (Security event 5145), manually created .wer files in the Windows Error Reporting ReportQueue, creation of phantom DLLs such as phoneinfo.dll in system paths, and WerMgr.exe spawning SYSTEM-integrity children. Organizations should collect the required Sysmon, Security, and Defender Operational telemetry; enable file-share object-access auditing; investigate these signals promptly; and validate the creating process, signer, file hash, and operational need before suppressing alerts.

Aug 19
Splunk Research

Detection: Windows Defender MpClient.dll Loaded by Non-Defender Process | Splunk Security Content

Aug 19
Splunk Research

Detection: Windows Alternate Data Stream Created Over Local Share | Splunk Security Content

Aug 19
Trendai Security

PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups | TrendAI (US)

Researchers detailed multiple China-aligned intrusion sets using modular tooling to compromise targets across Windows, web, and mobile environments. ESET said TheWizards used a tool called Spellbinder to abuse IPv6 SLAAC by sending rogue ICMPv6 Router Advertisements, positioning the attackers as the default gateway for adversary-in-the-middle operations. The group then intercepted DNS requests for Chinese software vendors and redirected update traffic so legitimate applications such as Tencent QQ and previously Sogou Pinyin fetched malicious payloads instead of real updates. The resulting infection chain used a downloader DLL, an encrypted blob, and in-memory loading of the WizardNet backdoor, which patched AMSI and ETW, supported modular execution, and injected shellcode into other processes while maintaining encrypted command-and-control. Separate reporting described broader China-linked operations using flexible malware delivery and post-compromise frameworks. Trend Micro tied Earth Minotaur to the MOONSHINE Exploit Kit and the DarkNimbus Android backdoor, while TrendAI documented PeckBirdy, a JScript-based framework used since 2023 across browsers, MSHTA, WScript, Classic ASP, Node.js, and .NET ScriptControl for watering-hole attacks, credential theft, lateral movement, reverse shells, and persistent backdoor access. PeckBirdy was observed in campaigns against Chinese gambling sites, Asian government entities, and private organizations, alongside modular backdoors HOLODONUT and MKDOOR. The reporting also noted infrastructure and tooling overlaps linking some of these activities to UNC3569, Earth Baxia, and supplier UPSEC, underscoring an ecosystem of China-aligned operators reusing shared malware, hijacking infrastructure, and fake software-update lures.

Aug 19
Trendai Security

The Rise of Collaborative Tactics Among China-aligned Cyber Espionage Campaigns | TrendAI (US)

Trend Micro and TrendAI reported that China-aligned espionage groups collaborated by passing live access to already-compromised networks between intrusion sets, a model Trend calls "Premier Pass-as-a-Service." In one cited case, Earth Estries breached a Southeast Asian government environment, deployed CrowDoor and related tooling, and then enabled follow-on activity tied to Earth Naga—also tracked as Flax Typhoon, RedJuliett, or Ethereal Panda—including ShadowPad infrastructure. The reporting says this approach differs from traditional initial access brokerage because downstream operators appear to receive direct access to victim assets rather than just stolen credentials or footholds. The activity aligns with separate reporting that RedJuliett intensified cyber espionage against Taiwanese organizations through exploitation of internet-facing network perimeter devices, while Trend Micro described Earth Estries as conducting long-term intrusions across government, telecommunications, and information service providers in APAC, Taiwan, and NATO countries. Researchers said the cooperative model can place multiple China-linked actors in the same intrusion chain or even the same process flow, complicating attribution and incident response, and they highlighted exploitation of Citrix devices including CVE-2025-5777 among the techniques used to gain or extend access.

Aug 18
Splunk Research

Detection: Windows Defender Threat Detected on Kernel Object Path | Splunk Security Content

Aug 18
Splunk Research

Detection: Windows Error Report Created in ReportQueue Manually | Splunk Security Content

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.