Last seven days
- First activity
- Aug 22, 2026
- Last activity
- Aug 29, 2026
- Feed role
- C2 / Distribution
- Host form
- 206 IP / 97 hostnames
Cobalt Strike is a commercial adversary-emulation and penetration-testing framework frequently abused in intrusions.
Profile source: Mallory opens in a new tabCobalt Strike
Cobalt Strike is a commercial adversary-emulation and penetration-testing framework frequently abused in intrusions. Its primary endpoint implant, Beacon, is an in-memory post-exploitation backdoor that can be reflectively loaded into processes and configured with malleable command-and-control profiles. Beacon supports command execution, host and user discovery, file transfer, keylogging, SOCKS proxying, port scanning, credential-access functions including Mimikatz integration, privilege escalation, process injection, and lateral movement. It supports command-and-control and staging through HTTP, HTTPS, DNS, SMB named pipes, and forward or reverse TCP, and Beacons can be chained through peer-to-peer communications. Cobalt Strike is broadly used by ransomware operators, financially motivated criminal groups, and espionage actors, including reported use by Conti, Warlock, and APT36-associated activity. It is commonly deployed as a secondary payload after initial compromise rather than serving as an initial-access mechanism itself. Cobalt Strike Beacon primarily targets Windows systems.
C2 tracking
Derp observations, rolling seven-day window
Samples
2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 30daba44a4a25ff5750508613f897057a55337458f19b562e2ed1172c77e626b 7126b9932dc0cdfe751340edfa7c4a14b69262eb1afd0530e6d1fdb2e25986dd 73ddf0df4e9e3866511ef9eae421b11615b81491d0db1d4a7ed19441e368ecef 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 3f050137b9f180dc883989c7717227cedfeb4c72ebfeca415578b8c5a875fa6a 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac baa739eba49601b21067818ff725e168894a0c186e90405180687cb26970f89a fc02692a98927272e200e01eb80007cc03aedbdec8acfb68aa9730dabaa8fce1 0ad712432bec3c13890fb14d7a878f58a6c8675739a87279736c39b56530cfcb Reported operators
GOSHELL описан как loader для Cobalt Strike Beacon с HTTP/S C2.
The compromised SharePoint worker process w3wp.exe spawned a Cobalt Strike beacon through DLL sideloading using MsMpSrv.exe and a malicious MsEdge.dll.
Cobalt Strike is a penetration testing tool that allows an attacker to deploy an agent named ‘Beacon’ on the target machine.
after which they deployed a Cobalt Strike beacon, carried out additional reconnaissance and lateral movement, and finally identified and exfiltrated the target organization’s files.
SNOWYAMBER first appeared in October 2022. It is a dropper ... and deploys Cobalt Strike and BruteRatel ... as second-stage payloads.
このPEファイルの実体はCobalt Strike Beaconでした。Cobalt Strikeは、正規のソフトウェアでありながら、その充実した機能から、不正規なライセンスにより攻撃者に悪用されている遠隔操作ソフトウェアです。
Many of the malware families were some bigger name malware such as: Zloader, IcedID, CobaltStrike (multiple actors, including Qakbot), NetSupportRAT, RemcosRAT, BazaarLoader
In their previous spear-phishing campaigns, the DLL is a component of the penetration testing tool Cobalt Strike, which they abuse to hijack the infected system.
2022-06-28 (TUESDAY) - TA578 ICEDID (BOKBOT) WITH BACKCONNECT, ANUBIS VNC AND COBALT STRIKE
Chimera has used scheduled tasks to invoke Cobalt Strike... and to maintain persistence.
"URL": "https://www.cobaltstrike.com/help-authorization-files" ... entries map authorization values to labels associated with malware and threat actors.
"URL": "https://www.cobaltstrike.com/help-authorization-files" ... entries map authorization values to labels associated with malware and threat actors.
"URL": "https://www.cobaltstrike.com/help-authorization-files" ... entries map authorization values to labels associated with malware and threat actors.
"URL": "https://www.cobaltstrike.com/help-authorization-files" ... entries map authorization values to labels associated with malware and threat actors.
CopyKittens uses rundll32 to load various tools on victims, including a lateral movement tool named Vminst, Cobalt Strike, and shellcode.
Cinnamon Tempest has used search order hijacking to launch Cobalt Strike Beacons. Storm-1811 ... sideloaded ... to load a Cobalt Strike beacon payload.
Storm-0501 has launched Cobalt Strike Beacon files using regsvr32.exe.
APT32 has also renamed a Cobalt Strike beacon payload to install_flashplayers.exe.
Зазначене призведе до ураження комп'ютера шкідливою програмою Cobalt Strike Beacon... notevil.dll (CS Beacon)
Cinnamon Tempest has used search order hijacking to launch Cobalt Strike Beacons. Storm-1811 ... sideloaded ... to load a Cobalt Strike beacon payload.
APT32 has also renamed a Cobalt Strike beacon payload to install_flashplayers.exe.
The New APT Group DarkCasino and the Global Surge in WinRAR 0-Day Exploits Cobalt Strike Konni
BRONZE ATLAS ... Tools ... Acehash, CCleaner v5.33 backdoor, ChinaChopper, Cobalt Strike, Dicey MSDN, Dodgebox, DUSTPAN, ForkPlayground, HUC Proxy Malware (Htran)
Similarly, a customized version of the CobaltStrike loader has been observed, possibly intended as a replacement for the Empire PowerShell framework previously used.
The first HTTP request to that domain is used to download a 261703 byte file... This turns out to be a Cobalt Strike beacon download... The output from 1768.py reveals that this Cobalt Strike beacon is using the following URIs for C2 communication.
Threat actors need only deliver Cobalt Strike’s Beacon – a highly configurable backdoor that allows attackers to quietly and remotely control endpoints and inject other attacker tools – as a payload of their chosen initial access vector.
a public malware sandbox run seems to show it receiving a “powershell” command that ultimately delivered a Cobalt Strike beacon... There has been some evidence suggesting NimzaLoader is being used to download and execute Cobalt Strike as its secondary payload
Threat actors need only deliver Cobalt Strike’s Beacon – a highly configurable backdoor that allows attackers to quietly and remotely control endpoints and inject other attacker tools – as a payload of their chosen initial access vector.
In almost all cases, the initial access brokers such as Trickbot and Bazar, dropped multiple Cobalt Strike beacons across the victim environment.
Threat actor used mostly Cobalt Strike and phishing emails and documents on behalf of Slovak National Security Authority... This DLL file is actually a Cobalt Strike Beacon.
UAC-0051 aka unc1151 (Cobalt Strike Beacon, MicroBackdoor)
Threat actor used mostly Cobalt Strike and phishing emails and documents on behalf of Slovak National Security Authority... This DLL file is actually a Cobalt Strike Beacon.
Threat actors need only deliver Cobalt Strike’s Beacon – a highly configurable backdoor that allows attackers to quietly and remotely control endpoints and inject other attacker tools – as a payload of their chosen initial access vector.
Similar to the majority of Baza campaigns, the tasks that were executed came in the form of cobalt strike stagers.
Secureworks CTU researchers conducted a focused investigation into malicious use of Cobalt Strike... Qakbot profiled the infected host, sent the profiled data to its C2 servers, and then downloaded and executed Cobalt Strike Beacon.
Some important things to track on the back of this leak to help defend your network. Cobalt Strike servers.
UAC-0051 aka unc1151 (Cobalt Strike Beacon, MicroBackdoor)
It makes use of Motnug and ChaCha20-based loaders, the CROSSWALK and SideWalk backdoors, along with Korplug (aka PlugX) and Cobalt Strike.
Like many other groups, OldGremlin used the Cobalt Strike framework to ensure that any post-exploitation activity was as effective as possible.
The newly discovered WarHawk backdoor contains various malicious modules that deliver Cobalt Strike... WarHawk is commissioned to deliver Cobalt Strike as the final payload.
TeleBoyi’s Arsenal ◆Malware ◆... ◆CobaltStrike ◆Sliver ◆AsyncRAT
Approximately 14 minutes after HTTPS traffic to the amazonAWS server, HTTPS Cobalt Strike traffic appeared on 23.106.215[.]123 over TCP port 443 using xenilik[.]com as the domain.
In this threat alert, the Cybereason team describes one attack scenario that started from a QBot infection, resulting in multiple key machines loading Cobalt Strike, which finally led to the global deployment of Black Basta ransomware.
The newly discovered WarHawk backdoor contains various malicious modules that deliver Cobalt Strike... WarHawk is commissioned to deliver Cobalt Strike as the final payload.
It was identified that this payload was a PlugX variant or a CobaltStrike Beacon as a post-exploitation framework.
...наступний PowerShell-скрипт, який, у свою чергу, забезпечить виконання шкідливої програми Cobalt Strike Beacon.
Running HR-Update.exe was a Cobalt Strike beacon. Cobalt Strike, a penetration testing tool, can also be used by attackers for gaining a foothold in the system. The final ransomware payload is downloaded with the help of Cobalt Strike.
Cobalt Strike Beacon : An off-the-shelf tool that can be used to execute commands, inject other processes, elevate current processes, or impersonate other processes, and upload and download files.
SigLoader and SodaMaster are still used in 2021 ○ Cobalt Strike, P8RAT and FYAntiLoader were not observed in 2021
Cobalt Strike Beacon - uses CloudFront infrastructure for its C&C activity (Cobalt Strike is an off-the-shelf tool that can be used to execute commands, inject other processes, elevate current processes, or impersonate other processes, and upload and download files)
This technique is commonly used by multiple intrusion sets to distribute... post-exploitation frameworks ( e.g. CobaltStrike, Sliver)...
on the 6 th of February we identified an extremely high number of prevention events stopping Cobalt Strike backdoor execution... downloaded and reflectively loaded Cobalt-Strike beacon with PowerShell extension directly into the memory.
During the months of May and June, Rancor continued to introduce new infection chains... In one case, the attackers turned to Cobalt Strike Beacon as their second stage payload.
the campaign adopts Cobalt Strike Beacon as the payload, enabling backdoor functionalities like C2 communication and command execution
What we refer to as Snatch malware comprises a collection of tooling, which include a ransomware component and a separate data stealer... a Cobalt Strike reverse-shell...
2018年4月下旬頃からmenuPass(APT10) が、多機能なペネトレーションテストツール Cobalt Strike を悪用した攻撃を行っていることが複数確認できました。
the campaign adopts Cobalt Strike Beacon as the payload, enabling backdoor functionalities like C2 communication and command execution
If the victim host belongs to an enterprise environment, it is more likely to drop remote management tool Atera and Cobalt Strike beacon, which would then lead to ransomware deployment.
In our context, Trickbot uses the highjacked wermgr.exe process to load a Cobalt Strike beacon into memory.
This loader has evolved as this threat group has taken advantage of multiple open source tools by altering the original application to execute payloads such as PyXie and/or Cobalt Strike.
In March, Cert-UA reported the group targeting state organizations in Ukraine using malicious implants called GrimPlant, GraphSteel and Cobalt Strike Beacon.
Casper is a modified version of the Cobalt Strike backdoor, showing the team server SHA1 hash if the controller connects to the C&C.
APT31 ... Examples of associated tools: Cobalt Strike, DopboxAES Rat, SalsaTrade, PakDoor ... ; Mustang Panda ... Examples of associated tools: Cobalt Strike, PlugX...
Use of Cobalt Strike BEACON malware... Installation of commercial/freemium internet remote desktop software • Cobalt Strike BEACON... Cobalt Strike Module: Loaded using one of two methods.
Further analysis of an SMB beacon used by DarkSide reveals Cobalt Strike PowerShell code.
The planted backdoors include Cobalt Strike or the NetSupport Manager remote access tool, but the group also uses their own ‘Bughatch’, ‘Wedgecut’, and ‘eck.exe”, and Burntcigar’ tools.
This loader has evolved as this threat group has taken advantage of multiple open source tools by altering the original application to execute payloads such as PyXie and/or Cobalt Strike.
These checks then determine which malware will be installed, if all the conditions are met and the script is likely inside an enterprise then for this instance it will install CobaltStrike and AteraAgent RAT... CobaltStrike was also found to be leveraged by this actor for enterprise environments.
The discovered samples are primarily Cobalt Strike Beacons, utilizing heavy control flow obfuscation – unlike the HelloXD ransomware samples we had previously seen.
실제 명령 및 제어 단계에서 사용하는 악성코드들도 CobaltStrike, Metasploit, Ladaon, BlueShell 등 모두 외부에 공개되어 있는 도구들이다.
The initial backdoor was used five minutes later to deploy the second stage tool: Cobalt Strike.
On the 2nd of January 2019 Cobalt Strike version 3.13 was released, which contained a fix for an “extraneous space”. This uncommon whitespace in its server responses represents one of the characteristics Fox-IT has been leveraging to identify Cobalt Strike Servers.
Their most common attack chain largely begins via EMOTET malspam campaigns, which then loads TrickBot and/or other loaders, and moves to attack tools like PowerShell Empire or Cobalt Strike to accomplish objectives relative to the victim organization under attack.
The first activity was seen on October 11, 2019, when a malicious PowerShell command was executed to install a CobaltStrike Beacon module to download the next stage payload.
In the figure above one can see an overlap with known entities in our Opencti database with the offensive framework Cobalt strike.
The group then abused the CyberArk Viewfinity software for DLL sideloading to load their custom HyperBro backdoor ... and used tools including Cobalt Strike.
Majority of the sightings were for Cobalt Strike C2 framework spanning across different Cobalt Strike Watermarks.
SLIME88 has targeted Taiwan’s energy sector through phishing emails and fake certificate installer, attempting to deploy backdoor programs such as AdaptixC2 and CobaltStrike.
Phase 3 — Exécution du Cobalt Strike Beacon (C2) ... Injection en mémoire d’un Cobalt Strike Beacon
Its toolkit already spanned ShadowPad, Cobalt Strike and the Biopass RAT...
RedFoxtrot utilise plusieurs méthodes et outils avec DcRat, notamment Cobalt Strike et AsyncRAT, pour l'infiltration et les activités de commande et de contrôle.
A distinctive characteristic of INC Ransom’s operations is its extensive use of Living-off-the-Land Binaries (LOLBins), Remote Monitoring and Management (RMM) tools, post-exploitation frameworks such as Cobalt Strike, and custom scripts designed to automate ransomware propagation.
The tool has been spotted delivering Cobalt Strike Beacon, a well known post exploitation framework, onto compromised machines.
Beyond the custom backdoor, the Rapid7 researchers observed the deployment of Cobalt Strike and Metasploit frameworks, noting that the campaign was characterized by highly surgical targeting of government, telecommunications, and financial sectors rather than a broad, indiscriminate infection of the general user base.
they executed a PowerShell command to download additional payloads from a remote location using a Cobalt Strike Beacon, maintaining persistence throughout this process using SystemBC.
In several cases, we observed the repeated deployment of Cobalt Strike beacons following successful compromise of organizational networks.
In one of the group’s attacks, we discovered traces of the Cobalt Strike framework, which the attackers used to contact their C2 and distribute malicious payloads.
One consistently observed method for establishing and maintaining a foothold was DNS BEACON. According to Cobalt Strike documentation, DNS beacons and listeners can be customized using Malleable C2 profiles.
TAG-112 compromised at least two Tibetan community websites ... This JavaScript prompted visitors to download a fake security certificate, which, when opened, deployed the Cobalt Strike payload.
Talos has so far found two types of payloads deployed by TetraLoader on the infected endpoints: Cobalt Strike beacons.
TAG-112 compromised at least two Tibetan community websites ... This JavaScript prompted visitors to download a fake security certificate, which, when opened, deployed the Cobalt Strike payload.
TAG-112 compromised at least two Tibetan community websites ... This JavaScript prompted visitors to download a fake security certificate, which, when opened, deployed the Cobalt Strike payload.
Cobalt Strike was also frequently used during the initial stage of an attack. Interestingly, we found that instead of the typical Cobalt Strike usage, Earth Krahang adds additional protection to their C&C server through the adoption of the open-source project RedGuard.
----[ 2.3 Private Cobalt Strike Beacon Drop Location: mnt/hgfs/Desktop/111/beacon This is a custom Cobalt Strike C2 Beacon.
APT29 has obtained and used a variety of tools including Mimikatz, SDelete, Tor, meek, and Cobalt Strike.
TEARDROP or RAINDROP backdoors would be deployed, which would install a customized Cobalt Strike beacon in the environment, enumerating the domain and allowing for the collection and exfiltration of information of value using hands-on-keyboard techniques.
APT29 has obtained and used a variety of tools including Mimikatz, SDelete, Tor, meek, and Cobalt Strike.
Several Cobalt Strike framework capabilities were utilized by the threat actor throughout the course of the attack, including RDP tunnelling for lateral movement, and process injection for the purposes of execution and evasion.
This industrialization of the cybercrime economy has made it easier for attackers to use ready-made penetration testing and other tools to perform their attacks. Within this category ... attackers using off-the-shelf tools, such as Cobalt Strike...
This industrialization of the cybercrime economy has made it easier for attackers to use ready-made penetration testing and other tools to perform their attacks. Within this category ... attackers using off-the-shelf tools, such as Cobalt Strike...
This industrialization of the cybercrime economy has made it easier for attackers to use ready-made penetration testing and other tools to perform their attacks. Within this category ... attackers using off-the-shelf tools, such as Cobalt Strike...
This industrialization of the cybercrime economy has made it easier for attackers to use ready-made penetration testing and other tools to perform their attacks. Within this category ... attackers using off-the-shelf tools, such as Cobalt Strike...
In nearly every single FIN12 intrusion since February 2020, FIN12 has used Cobalt Strike BEACON payloads to interact with victim networks, progressing through their attacks from internal reconnaissance to ransomware deployment.
Ultimately, the final stage drops a dangerous Cobalt Strike Beacon directly into memory . This implant establishes an outbound command-and-control connection to a remote server .
This is often followed by the deployment of Cobalt Strike BEACON on the compromised server to establish a foothold for further operations.
The weaponized tool used by Vice Society is Cobalt Strike, which allows the group to remotely access and control the infected endpoint.
The FBI also identified information relating to the download and execution of command and control (C2) malware such as DiceLoader, TrueBot, and Cobalt Strike Beacons, although it is unclear at which stage in the attack these tools were executed.
MITRE Software: Cobalt Strike.
For lateral movement, the threat actor used the Cobalt Strike penetration testing framework, and the freely available Adfind, BloodHound, and BITSadmin tools.
These attacks used the vulnerability, tracked as CVE-2021-40444, as part of an initial access campaign that distributed custom Cobalt Strike Beacon loaders.
Les attaquants ont utilisé leur accès de bureau à distance afin d’exécuter deux portes dérobées : SystemBC et Cobalt Strike.
Around three hours after execution of the initial IcedID malware, a cmd process was spawned from IcedID. This new process began beaconing to a Cobalt Strike server... Using the Cobalt Strike beacon, the threat actor looked up specific domain administrators... copied over a Cobalt Strike beacon to the domain controller and executed it.
The malware used in the incident was a simple but custom Cobalt Strike loader. ... we discovered several custom loaders of Cobalt Strike, including similar samples uploaded in VirusTotal.
SoundBill can be employed to decode and load any shellcode, including Cobalt Strike.
Dragos has also observed entities associated with XENOTIME experimenting with the Cobalt Strike penetration testing framework.
Across all known intrusions, UNC2628 has made heavy use of the Cobalt Strike framework and BEACON payloads.
The malware used in the incident was a simple but custom Cobalt Strike loader. ... we discovered several custom loaders of Cobalt Strike, including similar samples uploaded in VirusTotal.
CERT-UA said the malware gathers details including the computer name, operating system version, user account information, and running processes. The agency also warned that compromised systems could later receive a payload linked to the offensive hacking framework Cobalt Strike, a legitimate penetration-testing tool frequently abused by cybercriminals and state-backed groups.
Operators then manually decide whether to deliver a third-stage payload, typically a Cobalt Strike beacon, to high-value targets.
The name comes from the fact that it retrieves a Cobalt Strike beacon, from an attacker-controlled environment, disguised as a renderable image or hidden in a web-associated file type, like CSS, JS, or SVG.
The name comes from the fact that it retrieves a Cobalt Strike beacon, from an attacker-controlled environment, disguised as a renderable image or hidden in a web-associated file type, like CSS, JS, or SVG.
MirrorFace has used tools including the Secure Copy Protocol (SCP) client from PuTTY and Cobalt Strike.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Detects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.
Execution via WScript pulls a second-stage payload -- historically Cobalt Strike beacons, NetSupport RAT, or Python-based backdoors.
This exploit allowed the attackers to download or copy malicious components, which were then used to deploy customized Cobalt Strike payloads. Their modified Cobalt Strike version included altered signatures for evasion...
Cobalt Strike is a commercial penetration testing suite, that is sold for legitimate security audits of organizations. Since 2016, Cobalt Strike has been identified as being abused by many attack groups... An obfuscated VBS script located at https://files.browserupdate[.]download/a downloads a Cobalt Strike payload from the same server on port 443 and launches it.
China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors
China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors
China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors
These consist of Cobalt Strike Beacons, rootkits like KRNRAT and Moriya, as well as data exfiltration malware.
"Cobalt Strike is a commercial adversary simulation tool, long favored by both red teams and threat actors."
...TA575 criminal group is made up of prolific, financially-motivated opportunists who specialize in Dridex malware and operate swaths of Cobalt Strike servers.
"...offensive security tools such as Cobalt Strike, PowerSploit, Mimikatz, and Impacket..."
...deploy Spark RAT and Cobalt Strike Beacons...
"...targeting Chinese-speaking users with Cobalt Strike and Mimikatz payloads."
"With Hades attacks, GOLD DRAKE made extensive use of Cobalt Strike..."
"...offensive security tools such as Cobalt Strike, PowerSploit, Mimikatz, and Impacket..."
...deployed remote access tools such as Cobalt Strike or Sliver for remote and persistent access.
Third party reporting also suggests that the group has adopted tools including the ANEL backdoor and Cobalt Strike.
...deployed remote access tools such as Cobalt Strike or Sliver for remote and persistent access.
"The threat actor then used Cobalt Strike and Pypykatz..."
...deployed remote access tools such as Cobalt Strike or Sliver for remote and persistent access.
...often using loaders like Donut or Cobalt Strike.
...deployed remote access tools such as Cobalt Strike or Sliver for remote and persistent access.
"...the Buer Loader malware dropped qoipozincyusury.exe, a Cobalt Strike 'beacon'..."
"...used to sign Cobalt Strike and BYOVD-related malware uploaded to VirusTotal."
Ultimately, Microsoft says a Cobalt Strike beacon was deployed and used to spread laterally through the network while stealing data...
"In addition, Cobalt Strike is deployed as the preferred backdoor for post-exploitation."
APT32 malware has injected a Cobalt Strike beacon into Rundll32.exe.
"...used to sign Cobalt Strike and BYOVD-related malware uploaded to VirusTotal."
“…attempts to sell hacking tools, such as a modified version of Cobalt Strike.”
Exploited software
MITRE ATT&CK
Reporting
TrendAI reported that a newly identified threat actor, Void Arachne, is targeting Chinese-speaking users with trojanized Windows Installer packages masquerading as AI tools, Telegram Simplified Chinese language packs, Google Chrome, and VPN software including LetsVPN and QuickVPN. The campaign uses attacker-controlled websites, SEO poisoning, and Chinese-language Telegram channels to distribute the fake installers, exploiting demand for censorship-evasion tools and popular AI-driven applications such as nudifier, face-swapping, and voice-changing software. The MSI-based infection chain ultimately deploys the Winos 4.0 backdoor, giving the operators persistent access for command execution, surveillance, keylogging, and plugin-enabled follow-on activity. TrendAI said the malware establishes persistence through scheduled tasks and services, adds firewall rules and port forwarding, and communicates with command-and-control infrastructure associated with webcamcn[.]xyz. The activity aligns with the broader MITRE ATT&CK T1566.002 Spearphishing Link pattern in which malicious links and deceptive delivery pages are used to lure victims into downloading malware-bearing installers and follow-on payloads.
NightmareEclipse released ShieldBreak, a proof-of-concept local privilege-escalation exploit claimed to bypass Microsoft’s fix for CVE-2026-50656 (RoguePlanet). The exploit allegedly abuses improper link resolution during Windows Defender remediation, combining Cloud Files placeholders, Object Manager symbolic-link swaps, CLFS path handling, an EICAR-triggered scan, and NTFS alternate data streams to redirect a Defender process running as SYSTEM and plant C:\Windows\System32\phoneinfo.dll. A fabricated Windows Error Reporting report and the QueueReporting scheduled task then cause wermgr.exe to load the malicious DLL; the included Warden.dll payload reportedly duplicates a SYSTEM token and opens a SYSTEM shell in the unprivileged user’s session. Splunk published attack data and multiple disabled-by-default analytics for the ShieldBreak chain, covering Defender activity on \globalroot\ object-manager paths (Defender Operational events 1116/1117), MpClient.dll loaded by non-Defender processes, ADS creation through loopback administrative SMB shares (Security event 5145), manually created .wer files in the Windows Error Reporting ReportQueue, creation of phantom DLLs such as phoneinfo.dll in system paths, and WerMgr.exe spawning SYSTEM-integrity children. Organizations should collect the required Sysmon, Security, and Defender Operational telemetry; enable file-share object-access auditing; investigate these signals promptly; and validate the creating process, signer, file hash, and operational need before suppressing alerts.
Researchers detailed multiple China-aligned intrusion sets using modular tooling to compromise targets across Windows, web, and mobile environments. ESET said TheWizards used a tool called Spellbinder to abuse IPv6 SLAAC by sending rogue ICMPv6 Router Advertisements, positioning the attackers as the default gateway for adversary-in-the-middle operations. The group then intercepted DNS requests for Chinese software vendors and redirected update traffic so legitimate applications such as Tencent QQ and previously Sogou Pinyin fetched malicious payloads instead of real updates. The resulting infection chain used a downloader DLL, an encrypted blob, and in-memory loading of the WizardNet backdoor, which patched AMSI and ETW, supported modular execution, and injected shellcode into other processes while maintaining encrypted command-and-control. Separate reporting described broader China-linked operations using flexible malware delivery and post-compromise frameworks. Trend Micro tied Earth Minotaur to the MOONSHINE Exploit Kit and the DarkNimbus Android backdoor, while TrendAI documented PeckBirdy, a JScript-based framework used since 2023 across browsers, MSHTA, WScript, Classic ASP, Node.js, and .NET ScriptControl for watering-hole attacks, credential theft, lateral movement, reverse shells, and persistent backdoor access. PeckBirdy was observed in campaigns against Chinese gambling sites, Asian government entities, and private organizations, alongside modular backdoors HOLODONUT and MKDOOR. The reporting also noted infrastructure and tooling overlaps linking some of these activities to UNC3569, Earth Baxia, and supplier UPSEC, underscoring an ecosystem of China-aligned operators reusing shared malware, hijacking infrastructure, and fake software-update lures.
Trend Micro and TrendAI reported that China-aligned espionage groups collaborated by passing live access to already-compromised networks between intrusion sets, a model Trend calls "Premier Pass-as-a-Service." In one cited case, Earth Estries breached a Southeast Asian government environment, deployed CrowDoor and related tooling, and then enabled follow-on activity tied to Earth Naga—also tracked as Flax Typhoon, RedJuliett, or Ethereal Panda—including ShadowPad infrastructure. The reporting says this approach differs from traditional initial access brokerage because downstream operators appear to receive direct access to victim assets rather than just stolen credentials or footholds. The activity aligns with separate reporting that RedJuliett intensified cyber espionage against Taiwanese organizations through exploitation of internet-facing network perimeter devices, while Trend Micro described Earth Estries as conducting long-term intrusions across government, telecommunications, and information service providers in APAC, Taiwan, and NATO countries. Researchers said the cooperative model can place multiple China-linked actors in the same intrusion chain or even the same process flow, complicating attribution and incident response, and they highlighted exploitation of Citrix devices including CVE-2025-5777 among the techniques used to gain or extend access.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.