Cobalt Strike is a commercial adversary simulation and post-exploitation framework that is widely abused by threat actors as operational malware, most notably through its Beacon payload. Although designed for legitimate red-team use, cracked and unauthorized copies are routinely deployed in real intrusions across espionage, financially motivated, and ransomware operations. Beacon supports covert command-and-control, in-memory execution, process injection, credential access, reconnaissance, lateral movement, and delivery of follow-on actions during hands-on-keyboard operations. Its malleable C2 profiles, flexible staging, and support for Beacon Object Files make it adaptable to many intrusion chains and useful for defense evasion.
In malicious campaigns, Cobalt Strike commonly appears after an initial access malware family or phishing lure has established a foothold. It has been observed following loaders and botnets such as BazarLoader, Bumblebee, IcedID, QakBot, Emotet, Dridex, and Xiangoop Loader, and has also been delivered through exploit-driven chains and DLL side-loading. Threat actors have used it in spearphishing operations, thread-hijack email campaigns, malicious shortcut-based delivery, archive-based lures, and exploitation of vulnerabilities in client and server software. It is also used in Linux environments through CrossC2, which extends Beacon-like functionality beyond Windows.
Cobalt Strike is associated with a broad range of threat activity, including campaigns attributed to Tropic Trooper and intrusion sets involved in ransomware deployment such as Conti- and DoppelPaymer-linked operations. It is frequently used as a second-stage or post-compromise framework to maintain access, survey victim environments, move laterally, and prepare for data theft or ransomware execution. Its prevalence across unrelated actors and malware ecosystems makes it one of the most commonly encountered dual-use offensive frameworks in incident response.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
24 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The flaws are tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. | A Hive ransomware affiliate has been targeting Microsoft Exchange servers vulnerable to ProxyShell security issues... ProxyShell is a set of three vulnerabilities in the Microsoft Exchange Server that allow remote code execution without authentication on vulnerable deployments. The flaws are tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. | Following the exploitation of ProxyShell, the hackers planted four web shells in an accessible Exchange directory, and executed PowerShell code with high privileges to download Cobalt Strike stagers.
Tooling was identified on the server for exploiting CVE-2021-26855, commonly known as ProxyLogon. Upon successful exploitation, it is believed this actor will then deploy CobaltStrike as a means of maintaining access to target networks. A cracked copy of CobaltStrike was identified on the server...
Trend Micro uncovered a malicious Rich Text Format (RTF) file exploiting CVE-2017-11882 to deliver the spyware Loki (TSPY_LOKI). ... CVE-2017-11882 is a 17-year old memory corruption issue in Microsoft Office ... The flaw resides within Equation Editor (EQNEDT32.EXE) ... A proof-of-concept exploit was released publicly, but this has been fixed by Microsoft’s November Patch Tuesday. | In their previous spear-phishing campaigns, the DLL is a component of the penetration testing tool Cobalt Strike, which they abuse to hijack the infected system.
MTR observed Zloader leveraging a known vulnerability in Windows that enabled appending malicious script content to digitally signed files provided by Microsoft, CVE-2013-3900.
To quickly gain Windows domain admin credentials, Carmakal told BleepingComputer that the group had been seen using the Windows ZeroLogon vulnerability. For this reason, users must install necessary patches on all Windows servers.
The flaws are tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. | Following the exploitation of ProxyShell, the hackers planted four web shells in an accessible Exchange directory, and executed PowerShell code with high privileges to download Cobalt Strike stagers.
Mapping and Pivoting from Cobalt Strike C2 Infrastructure Attributed to CVE-2021-40444 ... https://www.trendmicro.com/en_us/research/21/i/remote-code-execution-zero-day--cve-2021-40444--hits-windows--tr.ht
The flaws are tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. | Following the exploitation of ProxyShell, the hackers planted four web shells in an accessible Exchange directory, and executed PowerShell code with high privileges to download Cobalt Strike stagers.
Starting late last week, we observed a large number of scans against our WebLogic honeypots to detect if they are vulnerable to CVE-2020-14882... we saw a small number of scans starting on Friday (Oct. 30th) attempting to install crypto-mining tools... Last Saturday we started seeing a campaign using a chain of Powershell obfuscated scripts to download a Cobalt Strike payload. | Last Saturday we started seeing a campaign using a chain of Powershell obfuscated scripts to download a Cobalt Strike payload.
On December 9, 2021, an RCE vulnerability was disclosed within the log4j package (CVE-2021-44228, CVE-2021-45046) which allows an attacker to execute arbitrary code on machines that utilize the logging functionality of the log4j package. | Case 2 - Cobalt Strike ... threat actors deployed Cobalt Strike beacons ... The malicious URL leads to an obfuscated PowerShell script ... This chunk of code is part of a Cobalt Strike shellcode.
The Zscaler ThreatLabz team has been actively monitoring exploit attempts related to the Apache Log4j 0-day Remote Code Execution Vulnerability (CVE-2021-44228), also known as “Log4Shell.” | In addition to the Mirai and Kinsing families, we have also seen reports of CobaltStrike and ransomware-related activity from these exploits.
Last Saturday we started seeing a campaign using a chain of Powershell obfuscated scripts to download a Cobalt Strike payload.
Note that abuse of wabmig.exe for the usage of Cobalt Strike has also been reported in the Follina case from Microsoft.
Versions 4.2 and 4.3 of Cobalt Strike’s server contain multiple Denial of Service vulnerabilities (CVE-2021-36798). The vulnerabilities can render existing Beacons unable to communicate with their C2 server, prevent new beacons from being installed, and have the potential to interfere with ongoing operations.
Compromised Infrastructure: Sharp Dragon shifts from dedicated servers to using compromised servers as Command and Control (C&C) servers, specifically using CVE-2023-0669 vulnerability, which is a flaw in the GoAnywhere platform allowing for pre-authentication command injection
2018年4月下旬頃からmenuPass(APT10) が、多機能なペネトレーションテストツール Cobalt Strike を悪用した攻撃を行っていることが複数確認できました。
In late October CIRCL got notified about MS Exchange servers vulnerable for the recent critical Exchange RCE vulnerabilities CVE-2021-26427. Microsoft Exchange Server Remote Code Execution Vulnerability
These payloads include: SystemBC malware, which acts as a dropper and socks proxy; Golang HTTP beacons, which seem to serve as a C2 framework; Socks proxy beacons, which can route connections; and a Beacon Object File (BOF), that was converted from a Cobalt Strike module to a standalone executable.
The vulnerabilities being targeted, which Microsoft has since issued patches for, are CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065... For example, in late April 2021, another cryptocurrency mining botnet, Prometei, was reported to be exploiting two of the aforementioned Exchange Server vulnerabilities (CVE-2021-27065 and CVE-2021-26858) which allowed the attackers to achieve remote code execution on the host.
The vulnerabilities being targeted, which Microsoft has since issued patches for, are CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065... For example, in late April 2021, another cryptocurrency mining botnet, Prometei, was reported to be exploiting two of the aforementioned Exchange Server vulnerabilities (CVE-2021-27065 and CVE-2021-26858) which allowed the attackers to achieve remote code execution on the host.
The vulnerabilities being targeted, which Microsoft has since issued patches for, are CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065. These vulnerabilities were reported on March 2, 2021 and affect Microsoft Exchange Server versions 2013, 2016 and 2019. They have been leveraged by multiple threat actors targeting Microsoft Exchange servers around the world.
Windows LSA Spoofing Vulnerability (CVE-2021-36942): An attacker could exploit EFSRPC (Encrypting File System Remote Protocol) to launch an NTLM relay attack dubbed PetitPotam, to escalate their system privileges... The privilege escalation tool EfsPotato exploits the CVE-2021-36942 vulnerability which is also known as PetitPotam.
Attacker exploited one vulnerability (CVE-2017-12824) of InPage to craft bait documents (.inp). | Another captured InPage vulnerability exploit document ends up executing a backdoor generated by Cobalt Strike.
Recently Cyble researchers came across a post where a researcher mentioned about fake Proof of Concept (POC) of CVE-2022-26809. Upon further investigation, we discovered that it’s malware disguised as an Exploit. | After printing the fake message, the malware executes the hidden PowerShell command using cmd.exe to deliver the actual payload. The below figure depicts the network communication to a command-and-control server for downloading the Cobalt-Strike Beacon.
59 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
このPEファイルの実体はCobalt Strike Beaconでした。Cobalt Strikeは、正規のソフトウェアでありながら、その充実した機能から、不正規なライセンスにより攻撃者に悪用されている遠隔操作ソフトウェアです。
Many of the malware families were some bigger name malware such as: Zloader, IcedID, CobaltStrike (multiple actors, including Qakbot), NetSupportRAT, RemcosRAT, BazaarLoader
In their previous spear-phishing campaigns, the DLL is a component of the penetration testing tool Cobalt Strike, which they abuse to hijack the infected system.
2022-06-28 (TUESDAY) - TA578 ICEDID (BOKBOT) WITH BACKCONNECT, ANUBIS VNC AND COBALT STRIKE
Chimera has used scheduled tasks to invoke Cobalt Strike... and to maintain persistence.
"URL": "https://www.cobaltstrike.com/help-authorization-files" ... entries map authorization values to labels associated with malware and threat actors.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
PSinjectの仕組み自体は以前実装したことがあり、Unmanaged Codeから.NET CLRを起動し、CLR経由でManaged Codeを実行する
APT29 has used encoded PowerShell scripts uploaded to CozyCar installations to download and install SeaDuke. APT29 also used PowerShell to create new tasks on remote machines, identify configuration settings, evade defenses, exfiltrate data, and to execute other commands. | AppleSeed has the ability to execute its payload via PowerShell... APT19 used PowerShell commands to execute payloads... APT28 downloads and executes PowerShell scripts and performs PowerShell commands... Start-Process / Invoke-Command / System.Management.Automation
EXCELファイルに偽装したショートカットファイルを確認すると、隠しフォルダに設定されていた&Recycle.Binフォルダ内の実行ファイルであるNTUSER.EXEを呼び出していることがわかります。
Our first case study of an actual campaign using MSBuild to deploy a payload is a Word document that displays a fairly common fake message prompting the user to 'enable content' to execute a VBA macro code included in the document. | The document is an HTML application written in VB Script that creates an MSBuild configuration file and runs MSBuild.
...or by proxying execution via callback on the user interface language enumerator (winnls.h), resulting in a standard Cobalt Strike stager. | Once this step has been completed, the malware executes the shellcode either via direct SYSCALLs...
Aucun processus enfant créé : la beacon tourne in-process via LoadLibrary
The target dll is chosen based on the size of its .text section to house the reflective payload and then it could execute the binary within a + RX section in that dll | Recent Injection Technique used by APT
Access Token Manipulation (ATT&CK technique: T1134) ... this section will explain how attackers can abuse access tokens and target the fundamental trust relationships in Windows domains to compromise entire networks. | If another privileged user is already logged on to the compromised host, an attacker can escalate their privileges and obtain a handle to an access token representing this user. Irrespective of whether the attacker impersonates the stolen token or starts a new process...
Obfuscated Files or Information T1027 Basic description To bypass security solutions, attackers employ obfuscation. | This complex type of startup is a technique known as Obfuscated Files or Information T1027.
To resolve the API Hashes manually, we need to determine the point where the hashes are finally resolved to an API Name. | Function calls within ShellCode are almost always made via API hashing. This means that there will be no function names within the code, as all calls are made via a hash and a hash-resolving function.
先述のショートカットファイルは、このNTUSER.EXEを実行すると同時に、偽のファイル(デコイファイル)を表示するよう仕組まれていました。利用者は、実際に表示されると想定していた文書ファイルが開かれたため、特に異常は感じないでしょう。 | 职工住房公积金缴存比例对应的月缴存额明细.xlsx.lnk(ショートカットファイル)... デフォルト設定のWindows OS環境では... .xlsxというファイルしか表示されません。
The target dll is chosen based on the size of its .text section to house the reflective payload and then it could execute the binary within a + RX section in that dll | Recent Injection Technique used by APT
Access Token Manipulation (ATT&CK technique: T1134) ... this section will explain how attackers can abuse access tokens and target the fundamental trust relationships in Windows domains to compromise entire networks. | If another privileged user is already logged on to the compromised host, an attacker can escalate their privileges and obtain a handle to an access token representing this user. Irrespective of whether the attacker impersonates the stolen token or starts a new process...
Loaderは、暗号化されたファイルを読み込み、実行できる形式に復元して実行する機能を持っています。... setting.datというファイルがありましたが、これが暗号化されたファイルで、このファイルをLoader機能が読み込むと復号され新たなマルウェアが動作を開始します。
This will reveal a .hta file. A .hta file is essentially an html file with an embedded script. | perform some hunting on the initial execution of .hta (mshta.exe parent process) to powershell.exe (child process).
攻撃者がもう一つ仕組んだテクニックがシステムファイル・システムフォルダを隠す機能の悪用です。... &Recycle.Binという名前のフォルダ... 隠しフォルダの設定がされており... 利用者には見た目上、フォルダの存在を確認することができません。
Once the criminals have established a solid foothold into the bank’s network, they then go on to perform lateral movement to identify and access other sub-networks, including the ATMs. | Once the hackers had taken control of the machines, they could remotely log into any ATM and upload the software of their choice.
C2concealer is a command line tool that generates randomized C2 malleable profiles for use in Cobalt Strike. | The hostname used in HTTP client and server side settings... HTTP Variants allow you to select different IOCs for http traffic on different beacons.
3,473 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a compatible command-and-control framework into which Vipere can integrate as a BOF.
Cobalt Strike beacons are described as post-exploitation tooling repurposed by attackers for remote access and follow-on intrusion activity after TrickBot infection.
Named as another malicious implant used by the same threat actor in related targeting of Ukrainian state organizations.
An intermediate in-memory stager used in the intrusion chain to dynamically resolve APIs via PEB traversal and ROR13 hashing, load WinINet, retrieve payloads from a remote staging node, and execute subsequent stages in memory while minimizing disk artifacts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.