Cobalt Strike Beacon is the payload component of the Cobalt Strike adversary simulation framework and is widely used as an in-memory backdoor by both red teams and threat actors. It supports command-and-control over multiple transports including HTTP, HTTPS, DNS, SMB, and TCP, and is commonly used after initial compromise to maintain access, execute commands, move laterally, escalate privileges, dump credentials, and stage additional tooling or payloads. Beacon is frequently deployed reflectively or loaded directly into memory by droppers, loaders, or shellcode launchers, and it is often paired with malleable C2 profiles to blend network traffic with legitimate services.
Beacon has been observed across a broad range of intrusion sets spanning espionage and financially motivated operations. Reported users include APT29, APT32, APT40, APT41, UNC2198, UNC2447, UNC2165, and other clusters that incorporated Beacon alongside custom malware, web shells, credential theft tools, and ransomware workflows. In these operations, Beacon has served as a first-stage or follow-on backdoor for persistence and operator control, including use as SMB Beacon for lateral movement and internal pivoting. It has also been delivered by malware such as DUSTPAN and memory-only droppers, and has been adapted for DLL proxying and sideload-style execution in Windows environments.
Beacon primarily targets Windows in the supplied reporting, though Beacon-style implants and related frameworks are also described on Linux and macOS in adjacent tooling contexts. In observed intrusions, Beacon has supported post-exploitation objectives against government, diplomatic, defense, maritime, technology, hospitality, consumer products, telecommunications, and other enterprise sectors. Its prevalence, flexibility, and support for in-memory execution have made it one of the most recognizable and operationally significant post-compromise implants in modern intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
First-stage backdoors such as AIRBREAK, FRESHAIR, and BEACON are used before downloading other payloads.
First-stage backdoors such as AIRBREAK, FRESHAIR, and BEACON are used before downloading other payloads.
First-stage backdoors such as AIRBREAK, FRESHAIR, and BEACON are used before downloading other payloads.
First-stage backdoors such as AIRBREAK, FRESHAIR, and BEACON are used before downloading other payloads.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Beacon This red team tool is based on the CobaltStrike beacon. A beacon is a CobaltStrike payload used by adversaries for several goals, such as persistence, execution, privilege escalation, credential dumping, lateral movement, and Command and Control (C2) communication over HTTP, HTTPS, DNS, SMB, and TCP protocols.
The DUSTPAN samples were configured to load BEACON payloads into memory that were encrypted using chacha20. The BEACON payloads, once executed, communicated using either self-managed infrastructure hosted behind Cloudflare or utilized Cloudflare Workers as their command-and-control (C2) channels.
UNC2165 also reportedly has used Beacon payloads and a command-and-control (C2) server other information security firms have linked to suspected Evil Corp activity...
"GOVERSHELL has already spawned five variants, including the most recent Beacon malware that could enable PowerShell command execution."
UNC2447 uses the Cobalt Strike BEACON HTTPSSTAGER implant for persistence to communicate with command-and-control (C2) servers over HTTPS...
UNC2198 has used Cobalt Strike BEACON, Metasploit METERPRETER, KOADIC, and PowerShell EMPIRE offensive security tools during this phase as well.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
DKMC is a tool that generates obfuscated shellcode that is stored inside of polyglot images. The image is 100% valid and also 100% valid shellcode.
MITRE ATT&CK Techniques ... T1036.005 Masquerading: Match Legitimate Name or Location
The most visible differences between a default profile and a custom profile Beacon configuration are the number of instructions and data transformations, as well as the HTTP parameters used.
Beacon communicates with an external team server to emulate command and control (C2) traffic. | The team server uses http-get and http-post transaction values to create actual HTTP requests and responses.
There are several HTTP transactions of GET and POST requests and responses.
dns-beacon: After Cobalt Strike v4.3, DNS options became part of the dns-beacon transaction. This transaction modifies the DNS C2 communication.
Domain fronting is a technique that attempts to disguise the traffic by smuggling data to a well-known service or domain.
With the Cobalt Strike payloads injected, the cybercriminals can then further traverse the target environment (move laterally) or pull-down additional tools and malware.
Figure 14 shows extracted configuration metadata for a custom profile Beacon... includes encoding types... Build Metadata: [7:Metadata, 11,5:tmp ] NETBIOS uppercase Parameter tmp
Next-Generation Firewalls with a Threat Prevention subscription can identify and block Cobalt Strike HTTP C2 requests as well as responses that are masked with the base64 encoding settings of the default profile
76 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The content references a named payload 'Beacon1.0.0', indicating a Beacon backdoor payload associated with the listed executables, script, domains, and IP infrastructure. No further behavioral detail is provided in the content.
Cross-platform C++ implant used by AdaptixC2 that supports BOF execution and multiple callback transports including HTTP/S, DNS, SMB named pipes, and TCP. It checks in with operator-controlled listeners for tasking and can execute commands and payloads in-memory.
A GOVERSHELL variant described as enabling PowerShell command execution.
BEACON is the main payload of Cobalt Strike, used for post-exploitation, command and control, and lateral movement. It is widely abused by threat actors for advanced attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.