Malware

Cobalt Strike

Also known as: Agentemis · BEACON · CobaltStrike · cobeacon

Cobalt Strike is a paid penetration testing product that allows an attacker to deploy an agent named 'Beacon' on the victim machine. Beacon includes a wealth of functionality to the attacker, including, but not limited to command execution, key logging, file transfer, SOCKS proxying, privilege escalation, mimikatz, port scanning and lateral movement. Beacon is in-memory/file-less, in that it consists of stageless or multi-stage shellcode that once loaded by exploiting a vulnerability or executing a shellcode loader, will reflectively load itself into the memory of a process without touching the disk. It supports C2 and staging over HTTP, HTTPS, DNS, SMB named pipes as well as forward and reverse TCP; Beacons can be daisy-chained. Cobalt Strike comes with a toolkit for developing shellcode loaders, called Artifact Kit. The Beacon implant has become popular amongst targeted attackers and criminal users as it is well written, stable, and highly customizable.

Indicators of Compromise 41

MITRE ATT&CK TTPs 40

T1003
OS Credential Dumping
Credential Access
T1018
Remote System Discovery
Discovery
T1021.001
Remote Desktop Protocol
Lateral Movement
T1021.002
SMB/Windows Admin Shares
Lateral Movement
T1027
Obfuscated Files or Information
Defense Evasion
T1033
System Owner/User Discovery
Discovery
T1046
Network Service Discovery
Discovery
T1048
Exfiltration Over Alternative Protocol
Exfiltration
T1053
Scheduled Task/Job
Execution
T1055
Process Injection
Defense Evasion
T1057
Process Discovery
Discovery
T1059.001
PowerShell
Execution
T1059.003
Windows Command Shell
Execution
T1070.001
Clear Windows Event Logs
Defense Evasion
T1071.001
Web Protocols
Command And Control
T1071.003
Mail Protocols
Command And Control
T1078
Valid Accounts
Defense Evasion
T1082
System Information Discovery
Discovery
T1083
File and Directory Discovery
Discovery
T1086
T1086
T1087.002
Domain Account
Discovery
T1105
Ingress Tool Transfer
Command And Control
T1110
Brute Force
Credential Access
T1110.003
Password Spraying
Credential Access
T1112
Modify Registry
Defense Evasion
T1133
External Remote Services
Persistence
T1204.002
Malicious File
Execution
T1218.001
Compiled HTML File
Defense Evasion
T1222
File and Directory Permissions Modification
Defense Evasion
T1222.001
Windows File and Directory Permissions Modification
Defense Evasion
T1482
Domain Trust Discovery
Discovery
T1484.001
Group Policy Modification
Defense Evasion
T1486
Data Encrypted for Impact
Impact
T1489
Service Stop
Impact
T1490
Inhibit System Recovery
Impact
T1537
Transfer Data to Cloud Account
Exfiltration
T1547.001
Registry Run Keys / Startup Folder
Persistence
T1562.001
Disable or Modify Tools
Defense Evasion
T1566
Phishing
Initial Access
T1573.001
Symmetric Cryptography
Command And Control

Source Articles

Cyberespionage campaign PassiveNeuron targets machines running Windows Server | Securelist
The PassiveNeuron campaign is a sophisticated cyberespionage operation targeting government, financial, and industrial organizations in Asia, Africa, and Latin America. It primarily compromises Windows Server machines, often through SQL server exploitation, and deploys custom APT implants such as Neursite and NeuralExecutor. The attackers use a multi-stage DLL loader chain with anti-sandbox techniques and have shifted to using GitHub-based dead drop resolvers for C2 configuration in newer variants. Attribution remains challenging, but TTPs suggest a Chinese-speaking threat actor with low confidence.
Kaspersky-labs
Uncovering Qilin attack methods exposed through multiple cases
The Qilin ransomware group, active since 2022 and operating as a Ransomware-as-a-Service (RaaS), has intensified its global operations in 2025, targeting primarily the manufacturing, professional services, and wholesale trade sectors. The group employs a double-extortion strategy, combining file encryption with data exfiltration, leveraging tools such as Mimikatz, Cyberduck, and Cobalt Strike. Initial access is suspected via compromised credentials on exposed VPNs without MFA, followed by extensive reconnaissance, credential dumping, lateral movement, and deployment of dual encryptors to maximize impact.
talos
Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
Cyber espionage campaigns targeting Pakistani law enforcement agencies, including the Balochistan Police, have been conducted by suspected China- and India-aligned threat actors between February 2024 and April 2026. The attackers exploited web applications such as the Complaint Management System to deploy custom malware, including PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. These operations targeted sensitive data including biometric records, criminal files, and personnel information, with infrastructure overlaps linking some activity to known threat groups like Mysterious Elephant. The compromise of public-facing portals extended the attack surface to both law enforcement and citizens.
hacker-news ·1mo ago
Maven Support Comes to GitHub Checks and OSS Package Search
The Java ecosystem is increasingly targeted by supply chain attacks, as demonstrated by the Shai-Hulud worm's second wave and a malicious lookalike of the Jackson JSON library published to Maven Central. These attacks leverage compromised or freshly published dependencies to deliver payloads such as Cobalt Strike, exploiting the window between publication and detection. Traditional vulnerability scanners are often too slow to respond, making real-time protection critical. StepSecurity now extends its Maven support to GitHub Checks and OSS Package Search to block compromised and newly published malicious Java dependencies during pull requests.
step-security ·2mo ago