Beacon is Cobalt Strike’s Windows post-exploitation implant, developed for adversary simulation and widely abused by cyberespionage and financially motivated threat actors. It provides remote command execution and command-and-control communications through HTTP, HTTPS, DNS, and SMB named pipes. Beacon supports staged and stageless deployment in x86 and x64 builds; staged deployments retrieve the payload through a stager and load it into memory. Configurable sleep intervals and jitter support asynchronous operation, while interactive sessions enable more immediate operator control.
Beacon supports process and shellcode injection, file upload and download, keystroke logging, screenshot capture, in-memory desktop control, timestamp modification, host and network enumeration, and port scanning. Credential operations include Mimikatz integration for password and hash recovery, local credential dumping, and DCSync. Its post-exploitation functionality also supports privilege escalation, access-token impersonation, pass-the-hash, Kerberos-ticket injection, and lateral movement through remote services, PowerShell, WinRM, and Windows Management Instrumentation. Browser pivoting can reuse authenticated Internet Explorer sessions, and proxying and port forwarding facilitate access to internal systems.
Beacon encrypts session metadata, tasking, and returned output. Malleable C2 profiles customize network characteristics, including HTTP headers, request patterns, data encoding, and certificate properties, allowing communications to resemble legitimate traffic or other malware. SMB Beacon instances can form peer-to-peer chains through a parent Beacon. Persistence in observed intrusions has involved scheduled tasks, service execution, and supporting loaders.
Beacon has been deployed following spearphishing, malicious macro execution, fake-update infection chains, exploitation, and compromise by other malware. APT41 has used DUSTPAN to load encrypted Beacon payloads into memory and route their communications through Cloudflare-protected infrastructure or Cloudflare Workers. Other documented users include APT29, APT32, APT40, UNC2198, and UNC2165. Its use spans diplomatic espionage, intrusions against manufacturing, consumer-products, hospitality, media and entertainment organizations, and ransomware-related operations; it is not exclusive to any single actor or industry.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“Beacon is Cobalt Strike’s payload to model advanced attackers. Use Beacon to egress a network over HTTP, HTTPS, or DNS.”
First-stage backdoors such as AIRBREAK, FRESHAIR, and BEACON are used before downloading other payloads.
First-stage backdoors such as AIRBREAK, FRESHAIR, and BEACON are used before downloading other payloads.
First-stage backdoors such as AIRBREAK, FRESHAIR, and BEACON are used before downloading other payloads.
First-stage backdoors such as AIRBREAK, FRESHAIR, and BEACON are used before downloading other payloads.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DUSTPAN ... loads an encrypted BEACON payloads into memory and once executed, communicate to its configured Command and Control (C2) server.
Beacon This red team tool is based on the CobaltStrike beacon. A beacon is a CobaltStrike payload used by adversaries for several goals, such as persistence, execution, privilege escalation, credential dumping, lateral movement, and Command and Control (C2) communication over HTTP, HTTPS, DNS, SMB, and TCP protocols.
UNC2165 also reportedly has used Beacon payloads and a command-and-control (C2) server other information security firms have linked to suspected Evil Corp activity...
"GOVERSHELL has already spawned five variants, including the most recent Beacon malware that could enable PowerShell command execution."
UNC2447 uses the Cobalt Strike BEACON HTTPSSTAGER implant for persistence to communicate with command-and-control (C2) servers over HTTPS...
UNC2198 has used Cobalt Strike BEACON, Metasploit METERPRETER, KOADIC, and PowerShell EMPIRE offensive security tools during this phase as well.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
The beacon includes a variety of functions like command execution, keylogging, file transfer, SOCKS proxying, privilege escalation, mimikatz, port scanning, and lateral movement.
DKMC is a tool that generates obfuscated shellcode that is stored inside of polyglot images. The image is 100% valid and also 100% valid shellcode.
"DUSTPAN is an in-memory dropper that decrypts and executes an embedded payload" and "DUSTTRAP... decrypts its Portable Executable (PE) file to execute in memory."
Usually, the Cobalt Strike beacon injects itself into any running process to evade detection and stay persistent.
The function GetCurrentProcessId() is used to get all process id along with ThreadId, the GetSystemTimeAsFileTime() to obtain current time. GetStartupInfoA is used to retrieve the content of the STARTUPINFO structure from when the calling process is created.
GetUserNameA is used to retrieve the name of the user associated with the thread.
The beacon includes a variety of functions like command execution, keylogging, file transfer, SOCKS proxying, privilege escalation, mimikatz, port scanning, and lateral movement.
To retrieve the name of the local computer GetComputerNameA API is used.
The malware extracts the name of the files in the current directory.
The most visible differences between a default profile and a custom profile Beacon configuration are the number of instructions and data transformations, as well as the HTTP parameters used.
HttpOpenRequestA is used to create an HTTP POST request handle. HttpOpenRequestA API is used to send the request to an HTTP server. The malware queries the server to determine the amount of data available using the InternetQueryDataAvailable API.
DUSTPAN loads BEACON into memory and, once executed, it communicates with its configured C2 server; the ATT&CK table lists Web Protocols for Command and Control.
dns-beacon: After Cobalt Strike v4.3, DNS options became part of the dns-beacon transaction. This transaction modifies the DNS C2 communication.
The beacon includes a variety of functions like command execution, keylogging, file transfer, SOCKS proxying, privilege escalation, mimikatz, port scanning, and lateral movement.
With the Cobalt Strike payloads injected, the cybercriminals can then further traverse the target environment (move laterally) or pull-down additional tools and malware.
Figure 14 shows extracted configuration metadata for a custom profile Beacon... includes encoding types... Build Metadata: [7:Metadata, 11,5:tmp ] NETBIOS uppercase Parameter tmp
76 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The content references a named payload 'Beacon1.0.0', indicating a Beacon backdoor payload associated with the listed executables, script, domains, and IP infrastructure. No further behavioral detail is provided in the content.
Cross-platform C++ implant used by AdaptixC2 that supports BOF execution and multiple callback transports including HTTP/S, DNS, SMB named pipes, and TCP. It checks in with operator-controlled listeners for tasking and can execute commands and payloads in-memory.
A GOVERSHELL variant described as enabling PowerShell command execution.
BEACON is the main payload of Cobalt Strike, used for post-exploitation, command and control, and lateral movement. It is widely abused by threat actors for advanced attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.