Cobalt Strike is a commercial adversary-simulation and post-exploitation framework used legitimately by red teams and widely abused by espionage actors and ransomware operators. Its Beacon implant provides remote command execution, file transfer, credential collection, keystroke logging, screenshot capture, and VNC-based desktop control on compromised Windows systems. The framework includes a Linux-hosted team server and operator clients for Windows, Linux, and macOS; these management platforms are distinct from Beacon’s target platform.
Beacon supports encrypted tasking and output over HTTP, HTTPS, DNS, and SMB named-pipe channels. Malleable C2 profiles customize communication patterns, data encoding, headers, and certificate characteristics. Staged and stageless payloads support in-memory execution, reflective DLL loading, and injection into selected processes. Post-exploitation functionality includes Windows and Active Directory enumeration, port scanning, credential dumping, pass-the-hash, token impersonation, Kerberos-ticket use, privilege escalation, and lateral execution through Windows services, WMI, and WinRM. Browser pivoting can reuse authenticated browser sessions, while proxying, port forwarding, and network bridging extend access into internal networks. Specific features vary by release.
Malicious deployments occur through phishing, intermediary loaders, exploitation of exposed applications, and SEO-poisoning infection chains. Documented users include APT29, APT32, Cobalt Group, FIN6, and ransomware affiliates, including LockBit and RansomHub operators. Cobalt Strike is not specific to one industry or threat actor; it commonly supplies interactive control and lateral-movement capabilities between initial compromise and subsequent data theft or ransomware deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
37 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In the incidents we investigated, the threat actor exploited the vulnerability (designated CVE-2019-18935) to deliver a Cobalt Strike beacon (in the form of a DLL payload) to disk.
OPERA1ER executed Invoke-EternalBlue command via Cobalt Strike framework. This command utilizes security issues patched by MS17-010 ... in 2021 these exploits are still relevant and the operator uses that way commonly.
Also known as Log4Shell, the vulnerability is now being used by threat actors linked to governments in China, Iran, North Korea, and Turkey, as well as access brokers used by ransomware gangs.
Запуск файла приводит к эксплуатации уязвимости CVE-2017-11882, которая позволяет злоумышленнику исполнить произвольный код с привилегиями пользователя, открывшего файл.
The Beacon has also been used in combination with exploits like CVE-2021-40444 and CVE-2022-30190 (Follina).
2024년 5월 HFS의 원격 코드 실행 취약점인 CVE-2024-23692가 공개되었으며 이를 활용할 경우 공격자는 HFS에 명령이 포함된 패킷을 전송하여 HFS가 악성 명령을 실행하도록 할 수 있다.
CVE-2023-46604 allows remote attackers with network access to a broker to execute arbitrary shell commands. This is achieved by exploiting serialized class types within the OpenWire protocol, which, in turn, leads to the broker instantiating any class available on the classpath.
The operation is using CVE-2017-8570 as the initial vector. The PPSX file includes a remote relationship to an external OLE object; the “script:” prefix before the HTTPS URL indicates use of this vulnerability.
The Beacon has also been used in combination with exploits like CVE-2021-40444 and CVE-2022-30190 (Follina).
CVE-2023-38831 is a vulnerability that enables malicious actors to execute arbitrary code when a user tries to access a harmless file contained within a ZIP archive.
从远程服务器下载89.0.4389.114版本的chrome浏览器,并且以无沙箱的方式启动chrome访问带有CVE-2021-21220漏洞触发页面……经过分析shellcode为Cobalt Strike远控。
Another similar attack from the InkySquid group (aka APT37, Reaper or ScarCruft) leveraged CVE-2021-26411 to attack Internet Explorer as well as legacy versions of Microsoft Edge, according to Volexity.
“MSTIC has observed activity by the nation-state actor MERCURY using the CVE-2020-1472 exploit (Zerologon) in active campaigns over the last 2 weeks,” according to Microsoft.
The threat actors successfully uploaded a WAR archive that housed a WebShell and various payloads into the webroot of the SysAid Tomcat web service by exploiting the SysAid CVE-2023-47246 Path Traversal vulnerability. | SysAid found supporting evidence indicating the utilization of the following PowerShell command to download and execute CobaltStrike.
An attacker “leveraged an older vulnerability for SharePoint (CVE-2019-0604) to exploit remotely unpatched servers” and implant a web shell, then deployed a Cobalt Strike-based payload and targeted domain controllers using Zerologon.
The script in question was originally invoked as remote code execution (RCE) during suspected CVE-2024-50623 exploitation.
“Cobalt Strike is adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors.”
The second, which ran from September 20 to 21, used an exploit for CVE-2017-8759 (patched last September), a code injection/remote code execution vulnerability in Microsoft’s .NET Framework. The vulnerability was used to retrieve and execute Cobalt Strike from a remote server they controlled. | The vulnerability was used to retrieve and execute Cobalt Strike from a remote server they controlled.
The attackers have been leveraging a Cityworks RCE vulnerability (CVE-2025-0994) to get access to the targeted environments and perform the initial reconnaissance.
We observed vulnerability CVE-2022-29464 being exploited in the wild since April, allowing unrestricted file uploads resulting to arbitrary remote code execution (RCE). | “Cobalt Strike beacons were also observed in both Linux and Windows environments. Since there is no official beacon provided for Linux, the compatible one we observed would have been prepared by the threat actor.”
The code, which the attackers camouflage around real content, is consistent with Internet Explorer bug CVE-2020-1380, the report said.
CVE-2024-1708 (CWE-22) — Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”). Base CVSS score of 8.4, still considered “High Priority”.
The report lists CVE-2011-4085 among the vulnerabilities highly likely exploited through JexBoss and describes it as a regression of CVE-2010-0738.
On April 19, 2023, PaperCut updated its advisory to report exploitation of CVE-2023-27350 in the wild. Sophos observed an affected customer as early as April 13, with Cobalt Strike detected during post-exploitation activity.
CVE-2015-7501 is identified as a deserialization vulnerability affecting Java environments using Apache Commons Collections, including JBoss-based environments, and as highly likely exploited through JexBoss.
In the first attack that Sophos analyzed, the threat actor exploited ProxyShell vulnerabilities in Exchange Server for remote access into a media organization in North America and deployed Cobalt Strike beacons.
ChamelGang used a known chain of vulnerabilities in Microsoft Exchange called ProxyShell—CVE-2021-34473, CVE-2021-34523, CVE-2021-31207—to compromise network nodes and gain a foothold.
CVE-2024-1709 (CWE-288) — Authentication Bypass Using Alternate Path or Channel. Base CVSS score of 10, indicating “Critical”.
Since January 2025, an unidentified threat actor has been targeting organizations in Japan by exploiting CVE-2024-4577, a remote code execution (RCE) flaw in the PHP-CGI implementation on Windows, to gain initial access.
The CSIRT considers it highly probable that JexBoss exploited CVE-2010-0738, an improper-access-control vulnerability affecting the exposed JBoss JMX console through version 5.1.x.
ChamelGang used a known chain of vulnerabilities in Microsoft Exchange called ProxyShell—CVE-2021-34473, CVE-2021-34523, CVE-2021-31207—to compromise network nodes and gain a foothold.
The report identifies CVE-2017-12149 as remote code execution via deserialization involving JMXInvokerServlet and records numerous HTTP GET and POST requests to /invoker/JMXInvokerServlet.
The document provides insight into the usage (misuse) of Cobalt Strike, a legitimate post exploitation tool used by red teams.
“More recently, Earth Lamia also exploited CVE-2025-31324 (SAP NetWeaver Visual Composer unauthenticated file upload vulnerability).” The attribution discussion connects exploitation campaigns to Cobalt Strike infrastructure and a VShell deployment involving the SNOWLIGHT stager.
Три команды внутренней разведки и передачи данных были запущены в результате эксплуатации уязвимости в SharePoint CVE-2021-27076 после загрузки Cobalt Strike; инфраструктурный IP ранее связывался другими исследователями с группировкой Thor. | Hacking Cat used Cobalt Strike before Gorilla RAT. Cobalt Strike C2 infrastructure also appeared alongside Monkey Ransomware, and several associated commands were launched following exploitation of SharePoint CVE-2021-27076.
Earth Krahang is known to conduct spear-phishing attacks and exploiting vulnerable public-facing servers such as Oracle Web Applications Desktop Integrator CVE-2022-21587 (CVSS 9.8) ... to install backdoors such as Cobalt Strike, RESHELL, and XDealer. | Earth Krahang exploits vulnerable servers "to install backdoors such as Cobalt Strike, RESHELL, and XDealer." The advisory additionally lists Earth Krahang Cobalt Strike C&C servers.
Earth Krahang is known to conduct spear-phishing attacks and exploiting vulnerable public-facing servers such as ... OpenFire CVE-2023-32315 (CVSS 7.5) to install backdoors such as Cobalt Strike, RESHELL, and XDealer. | Earth Krahang exploits vulnerable servers "to install backdoors such as Cobalt Strike, RESHELL, and XDealer." The advisory additionally lists Earth Krahang Cobalt Strike C&C servers.
67 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cobalt Strike can spawn a job to inject into LSASS memory and dump password hashes.
The vulnerability was used to retrieve and execute Cobalt Strike from a remote server they controlled.
“The intrusion set uses COBALT STRIKE to exfiltrate the data collected through the DNS protocol.”
Tool acquisition can involve the procurement of commercial software licenses, including for red teaming tools such as Cobalt Strike.
The actor predominantly relies on open source adversary emulation frameworks, such as Cobalt Strike, Havoc, and others.
APT32 malware has injected a Cobalt Strike beacon into Rundll32.exe. Cobalt Strike can inject a variety of payloads into processes dynamically chosen by the adversary.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
SYSTEM cmd.exe /c "powershell -NonInteractive -EncodedCommand <base64_data>"
Used WMIC to invoke PowerShell to download a file named 01.css and 02.css ... Behavioral detections such as Exec_27a (Mitre ATT&CK T1059.001).
%windir%\system32\cmd.exe /c start rundll32.exe mkl2n.dll,kXlNkCKgFC
Defensive Evasion T1027.002 Software Packing Unpacked the Cobalt Beacon using CryptDecrypt
ImagingDevices.exe was launched via WmiPrivse.exe and a Meterpreter agent was injected into the process.
Upon clicking the file, it launches an LNK file by using Mshta.exe utility that leads to the execution of the HTA file.
The sample is a DLL that executes using Regsvr32. Most of the important logic is inside DllRegisterServer.
CL0P actors use Cobalt Strike to expand network access after gaining access to the Active Directory (AD) servers.
The loader attempts to terminate the parent process (anti-debugging), iterating over running processes and looking for itself.
System utilities used for discovery included: ... systeminfo
Lateral movement was then performed over SMB, to transfer a Cobalt Strike Beacon DLL’s to other workstation’s C$\ProgramData\.
Cyber threat actors use cobalt strike to authenticate valid accounts.
Cyber threat actors use cobalt strike to hijack remote sessions using SSH and RDP hijacking methods.
"Method 1": "GET" ... "Method 2": "POST" ... "Beacon Type": "8 (HTTPS)"
The attacker uses Chisel (SOCKS5 proxy connection on a secure channel like http/ssh, tunneling traffic through firewall for hidden communication) with Cobalt Strike.
Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).
Konni actors start downloading a final payload by contacting its C2 server.
Attackers ... may deploy remote-access or backdoor frameworks such as Cobalt Strike or SystemBC before encryption. The MITRE context lists "Remote Access Software".
4,003 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Offensive tool deployed by QakBot operators to provide interactive network access. The article also recommends hunting for its beacons during investigation of loader infections.
Used as an example of why an open port is insufficient evidence of malicious infrastructure. The results do not establish that the matching addresses actually host Cobalt Strike.
Mentioned solely as an established offensive framework that inspired graphcat's user interface.
CyberXero integrated Cobalt Strike with AI-assisted attack tooling. The reported infrastructure included a Team Server, an HTTPS beacon endpoint, HTTP staging, and PowerShell stager delivery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.