Cobalt Strike is a commercial adversary simulation framework whose Beacon payload is widely repurposed as post-compromise malware by criminal and state-linked operators. In intrusion reporting it commonly appears as an in-memory implant used after initial access to provide remote command execution, operator tasking, payload delivery, reconnaissance, credential access, lateral movement, and broader post-exploitation control. Although originally designed for red-team use, it has become one of the most prevalent dual-use toolsets in real-world intrusions and carries little standalone attribution value because it is used by many unrelated actors.
Beacon is frequently deployed through loaders, web shells, exploit chains against internet-facing applications, and DLL sideloading, and is often executed directly in memory to reduce forensic visibility. Reported campaigns show it being launched after exploitation of exposed enterprise software, after malicious implants disguised as updates, and alongside legitimate remote-management tools and administrative utilities. Operators have used Cobalt Strike in espionage intrusions against government, telecommunications, law enforcement, defense, and other enterprise targets, as well as in financially motivated ransomware operations.
Observed activity links Cobalt Strike to multiple threat contexts. China-nexus operations have used it in telecom intrusions and in espionage targeting Pakistani law enforcement infrastructure. It has also appeared in campaigns exploiting TeamCity and other public-facing enterprise systems, and in ransomware operations such as Medusa for internal spread and post-compromise control. Cross-platform extensions such as CrossC2 have also been associated with Beacon, but the supplied facts directly support Windows use most clearly.
Because Cobalt Strike is a framework rather than a single-purpose commodity trojan, its operational role is best characterized as a remote-access and post-exploitation implant. Defenders typically encounter it as Beacon shellcode or a Beacon-loaded process providing covert command-and-control, staging of additional payloads, and hands-on-keyboard intrusion support.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
External User Tags #cobaltstrike
In addition, threat actors were observed scanning and exploiting vulnerabilities in various enterprise software and network appliances, including: Joomla CMS – CVE-2023-23752
In addition, threat actors were observed scanning and exploiting vulnerabilities in various enterprise software and network appliances, including: Zimbra Collaboration Suite – CVE-2022-27925
Observed attacks have targeted a range of widely deployed platforms, including: Microsoft SharePoint (e.g. CVE-2021-27076)
Observed attacks have targeted a range of widely deployed platforms, including: GeoServer (e.g. CVE-2024-36401)
In addition, threat actors were observed scanning and exploiting vulnerabilities in various enterprise software and network appliances, including: Jenkins – CVE-2024-23897
In addition, threat actors were observed scanning and exploiting vulnerabilities in various enterprise software and network appliances, including: Microsoft Exchange Server – CVE-2022-41082
In addition, threat actors were observed scanning and exploiting vulnerabilities in various enterprise software and network appliances, including: React Server Components – CVE-2025-55182
In addition, threat actors were observed scanning and exploiting vulnerabilities in various enterprise software and network appliances, including: Fortinet FortiOS – CVE-2022-40684, CVE-2024-21762
Observed attacks have targeted a range of widely deployed platforms, including: Openfire Server (e.g. CVE-2023-32315)
In addition, threat actors were observed scanning and exploiting vulnerabilities in various enterprise software and network appliances, including: F5 BIG-IP – CVE-2023-46747
In addition, threat actors were observed scanning and exploiting vulnerabilities in various enterprise software and network appliances, including: Hikvision products – CVE-2021-36260
Observed attacks have targeted a range of widely deployed platforms, including: Microsoft Exchange Server (e.g. CVE-2021-26855, ProxyLogon)
In addition, threat actors were observed scanning and exploiting vulnerabilities in various enterprise software and network appliances, including: Apache Shiro – CVE-2016-4437
In addition, threat actors were observed scanning and exploiting vulnerabilities in various enterprise software and network appliances, including: Fortinet FortiOS – CVE-2022-40684, CVE-2024-21762
In addition, threat actors were observed scanning and exploiting vulnerabilities in various enterprise software and network appliances, including: Cisco IOS XE Web UI – CVE-2023-20198
APT29 (Cozy Bear) exploited CVE-2024-27198 in real-world campaigns.
CVE-2021-40444 - пример атаки, где вредоносный документ не содержит макросов... Эксплойт использует уязвимость в MSHTML для удалённого выполнения кода через вредоносный ActiveX-контроль... Включена в каталог CISA KEV (активно эксплуатируется в дикой среде), связана с ransomware-кампаниями... По данным Microsoft MSTIC и Mandiant, CVE-2021-40444 использовалась для доставки Cobalt Strike Beacon | По данным Microsoft MSTIC и Mandiant, CVE-2021-40444 использовалась для доставки Cobalt Strike Beacon в целевых кампаниях.
Member-only story Follina (CVE-2022–30190) & Cobalt Strike C2 -Simple Analysis ... Twitter Intel Initial Access Follina Exploit CVE-2022–30190
50 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
На серверах (за пределами сетевых устройств) Salt Typhoon разворачивает бэкдор GhostSpider (по данным Trend Micro, разработан специально для телеком-сетей), руткит Demodex (kernel-mode), Cobalt Strike, а также SnappyBee и HemiGate.
Shellcode: PEB walk + export hash resolver + 54 internal functions ... Second-stage payload (likely a follow-on PE or Cobalt Strike beacon)
In this particular campaign, APT29 used VaporRage to distribute Cobalt Strike beacons to further establish a foothold within the environment.
The tool has been spotted delivering Cobalt Strike Beacon, a well known post exploitation framework, onto compromised machines.
Beyond the custom backdoor, the Rapid7 researchers observed the deployment of Cobalt Strike and Metasploit frameworks, noting that the campaign was characterized by highly surgical targeting of government, telecommunications, and financial sectors rather than a broad, indiscriminate infection of the general user base.
they executed a PowerShell command to download additional payloads from a remote location using a Cobalt Strike Beacon, maintaining persistence throughout this process using SystemBC.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
These hashes empower server clustering, identification of unique and similar servers, and the pursuit of malicious actors with heightened confidence.
HTTP-Basma’s algorithm's core idea centers on sending 8 specially crafted HTTP requests with varying requirements to elicit different responses from the server.
The researchers grouped the intrusions into four clusters based on the malware and infrastructure involved: PlugX, ShadowPad, Cobalt Strike, and Remcos.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Since encoded commands are often long, set a threshold (e.g., 1000 characters) to flag suspiciously long commands.
180秒スリープした後に、外部サーバに HTTP GET でアクセスしダウンロードしたコードを新たに起動した Explorer.exeに インジェクションする。 (Process Hollowing)
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
During this time period, multiple rounds of enumeration and lateral movement occurred using Cobalt Strike.
Following initial access, attackers typically perform: Active Directory enumeration
Its analysis of command-and-control netflow data revealed four tooling clusters converging on this victim class: PlugX, ShadowPad, Cobalt Strike, and Remcos.
1,087 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial offensive framework used as a RAT/C2 implant in APT campaigns.
Post-exploitation tooling whose servers were attributed in the content to suspected China-nexus actors targeting Pakistani law enforcement.
A widely used post-exploitation framework deployed by SharkLoader to provide remote command execution and support reconnaissance, credential harvesting, lateral movement, and further compromise.
Post-exploitation tooling used alongside remote-management software and PsExec to support Medusa intrusion activity and spread.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.