Cobalt Strike is a commercial adversary-emulation and penetration-testing platform frequently abused by criminal and state-aligned threat actors. Its Beacon agent functions as an in-memory post-exploitation backdoor, supporting command execution, file transfer, host and user discovery, process injection, keylogging, SOCKS proxying, port scanning, credential-access tooling, privilege escalation, and lateral movement. Beacon can communicate through HTTP, HTTPS, DNS, SMB named pipes, and forward or reverse TCP, and its malleable C2 profiles enable operators to customize network behavior. Threat actors have deployed Cobalt Strike following ClickFix social-engineering access and have used it extensively in ransomware intrusions, including operations associated with Conti and Warlock. Observed use commonly targets Windows enterprise environments across government, technology, financial-services, manufacturing, education, and other sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
26 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-28252 is an out-of-bounds write elevation-of-privilege vulnerability in Windows Common Log File System (CLFS), actively exploited in the wild to gain SYSTEM privileges and deploy Nokoyawa ransomware.
The actors behind the recent Truebot campaign have shifted their delivery mechanism and are now exploiting a vulnerability in the on-premises and cloud-based IT system auditing software, Netwirx Auditor. The vulnerability, tracked as CVE-2022-31199 (CVSS: 9.8), is a Remote Code Execution (RCE) vulnerability that would enable a remote unauthenticated threat actor to execute code on vulnerable systems.
Researchers have observed threat actors exploiting the more severe of the two vulnerabilities, CVE-2023-27350, to deliver the LockBit strain of ransomware. CVE-2023-27350 enables remote code execution (RCE); attackers leveraged it to run a PowerShell script that allows them to download and execute a file containing malicious payload analysts identified as the LockBit strain of ransomware. | after which they deployed a Cobalt Strike beacon, carried out additional reconnaissance and lateral movement, and finally identified and exfiltrated the target organization’s files.
eSentire has recently observed active exploitation attempts targeting the WinSock File Transfer Protocol (WS_FTP) vulnerability CVE-2023-40044. Observed attacks resulted in the attempted deployment of the Metasploit payload Meterpreter and the adversary simulation tool Cobalt Strike. CVE-2023-40044 (CVSS: 10) is classified as a WS_FTP .NET Deserialization vulnerability in the Ad Hoc Transfer Module. Exploitation would allow an unauthenticated threat actor to achieve remote command execution on the underlying operating system of the WS_FTP Server.
We have previously published a blog on what organizations need to know about the actively exploited CVE-2025-55182, which is a critical (CVSS 10.0) pre-authentication remote code execution vulnerability affecting React Server Components (RSC) used in React.js, Next.js, and related frameworks. | In a few cases on Linux hosts, we’ve observed threat actors exploiting the vulnerability to execute Cobalt Strike beacons generated with CrossC2, software that builds cross-platform payloads for Cobalt Strike.
The flaws are tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. | A Hive ransomware affiliate has been targeting Microsoft Exchange servers vulnerable to ProxyShell security issues... ProxyShell is a set of three vulnerabilities in the Microsoft Exchange Server that allow remote code execution without authentication on vulnerable deployments. The flaws are tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. | Following the exploitation of ProxyShell, the hackers planted four web shells in an accessible Exchange directory, and executed PowerShell code with high privileges to download Cobalt Strike stagers.
Tooling was identified on the server for exploiting CVE-2021-26855, commonly known as ProxyLogon. Upon successful exploitation, it is believed this actor will then deploy CobaltStrike as a means of maintaining access to target networks. A cracked copy of CobaltStrike was identified on the server...
Trend Micro uncovered a malicious Rich Text Format (RTF) file exploiting CVE-2017-11882 to deliver the spyware Loki (TSPY_LOKI). ... CVE-2017-11882 is a 17-year old memory corruption issue in Microsoft Office ... The flaw resides within Equation Editor (EQNEDT32.EXE) ... A proof-of-concept exploit was released publicly, but this has been fixed by Microsoft’s November Patch Tuesday. | In their previous spear-phishing campaigns, the DLL is a component of the penetration testing tool Cobalt Strike, which they abuse to hijack the infected system.
MTR observed Zloader leveraging a known vulnerability in Windows that enabled appending malicious script content to digitally signed files provided by Microsoft, CVE-2013-3900.
To quickly gain Windows domain admin credentials, Carmakal told BleepingComputer that the group had been seen using the Windows ZeroLogon vulnerability. For this reason, users must install necessary patches on all Windows servers.
The flaws are tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. | Following the exploitation of ProxyShell, the hackers planted four web shells in an accessible Exchange directory, and executed PowerShell code with high privileges to download Cobalt Strike stagers.
Mapping and Pivoting from Cobalt Strike C2 Infrastructure Attributed to CVE-2021-40444 ... https://www.trendmicro.com/en_us/research/21/i/remote-code-execution-zero-day--cve-2021-40444--hits-windows--tr.ht
The flaws are tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. | Following the exploitation of ProxyShell, the hackers planted four web shells in an accessible Exchange directory, and executed PowerShell code with high privileges to download Cobalt Strike stagers.
Starting late last week, we observed a large number of scans against our WebLogic honeypots to detect if they are vulnerable to CVE-2020-14882... we saw a small number of scans starting on Friday (Oct. 30th) attempting to install crypto-mining tools... Last Saturday we started seeing a campaign using a chain of Powershell obfuscated scripts to download a Cobalt Strike payload. | Last Saturday we started seeing a campaign using a chain of Powershell obfuscated scripts to download a Cobalt Strike payload.
On December 9, 2021, an RCE vulnerability was disclosed within the log4j package (CVE-2021-44228, CVE-2021-45046) which allows an attacker to execute arbitrary code on machines that utilize the logging functionality of the log4j package. | Case 2 - Cobalt Strike ... threat actors deployed Cobalt Strike beacons ... The malicious URL leads to an obfuscated PowerShell script ... This chunk of code is part of a Cobalt Strike shellcode.
The Zscaler ThreatLabz team has been actively monitoring exploit attempts related to the Apache Log4j 0-day Remote Code Execution Vulnerability (CVE-2021-44228), also known as “Log4Shell.” | In addition to the Mirai and Kinsing families, we have also seen reports of CobaltStrike and ransomware-related activity from these exploits.
Last Saturday we started seeing a campaign using a chain of Powershell obfuscated scripts to download a Cobalt Strike payload.
Note that abuse of wabmig.exe for the usage of Cobalt Strike has also been reported in the Follina case from Microsoft.
Versions 4.2 and 4.3 of Cobalt Strike’s server contain multiple Denial of Service vulnerabilities (CVE-2021-36798). The vulnerabilities can render existing Beacons unable to communicate with their C2 server, prevent new beacons from being installed, and have the potential to interfere with ongoing operations.
Compromised Infrastructure: Sharp Dragon shifts from dedicated servers to using compromised servers as Command and Control (C&C) servers, specifically using CVE-2023-0669 vulnerability, which is a flaw in the GoAnywhere platform allowing for pre-authentication command injection
2018年4月下旬頃からmenuPass(APT10) が、多機能なペネトレーションテストツール Cobalt Strike を悪用した攻撃を行っていることが複数確認できました。
In late October CIRCL got notified about MS Exchange servers vulnerable for the recent critical Exchange RCE vulnerabilities CVE-2021-26427. Microsoft Exchange Server Remote Code Execution Vulnerability
These payloads include: SystemBC malware, which acts as a dropper and socks proxy; Golang HTTP beacons, which seem to serve as a C2 framework; Socks proxy beacons, which can route connections; and a Beacon Object File (BOF), that was converted from a Cobalt Strike module to a standalone executable.
The vulnerabilities being targeted, which Microsoft has since issued patches for, are CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065... For example, in late April 2021, another cryptocurrency mining botnet, Prometei, was reported to be exploiting two of the aforementioned Exchange Server vulnerabilities (CVE-2021-27065 and CVE-2021-26858) which allowed the attackers to achieve remote code execution on the host.
The vulnerabilities being targeted, which Microsoft has since issued patches for, are CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065... For example, in late April 2021, another cryptocurrency mining botnet, Prometei, was reported to be exploiting two of the aforementioned Exchange Server vulnerabilities (CVE-2021-27065 and CVE-2021-26858) which allowed the attackers to achieve remote code execution on the host.
The vulnerabilities being targeted, which Microsoft has since issued patches for, are CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065. These vulnerabilities were reported on March 2, 2021 and affect Microsoft Exchange Server versions 2013, 2016 and 2019. They have been leveraged by multiple threat actors targeting Microsoft Exchange servers around the world.
56 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The indicators of compromise list identifies CobaltStrike loader hashes and CobaltStrike C2 servers associated with the activity.
The compromised SharePoint worker process w3wp.exe spawned a Cobalt Strike beacon through DLL sideloading using MsMpSrv.exe and a malicious MsEdge.dll.
Cobalt Strike is a penetration testing tool that allows an attacker to deploy an agent named ‘Beacon’ on the target machine.
after which they deployed a Cobalt Strike beacon, carried out additional reconnaissance and lateral movement, and finally identified and exfiltrated the target organization’s files.
SNOWYAMBER first appeared in October 2022. It is a dropper ... and deploys Cobalt Strike and BruteRatel ... as second-stage payloads.
38 distinct techniques documented for this family, organized by ATT&CK tactic.
The beacon includes a variety of functions like command execution, keylogging, file transfer, SOCKS proxying, privilege escalation, mimikatz, port scanning, and lateral movement.
These included the names, hashes, and sizes of the files involved, the URLs that served downloads of the malicious files, and the Cobalt Strike C2 domains used in the campaign’s later stages.
“On 16 August 2023, three Word documents containing malicious macros were uploaded to VirusTotal in short succession.”
Miraak implements a compatibility layer for Cobalt Strike Beacon Object Files (BOFs)... to load and execute existing BOF modules within the Miraak agent itself.
The extracted configuration contains a “process-inject” section with allocator “NtMapViewOfSection” and execution methods including CreateThread, NtQueueApcThread-s, CreateRemoteThread, and RtlCreateUserThread.
The process-injection execute configuration includes “CreateRemoteThread.”
The process-injection execute configuration includes “CreateThread 'ntdll!RtlUserThreadStart'” and “CreateThread.”
Cobalt Strike encoded data was concealed in a jQuery script, and legitimate tools were renamed to appear benign.
The extracted configuration contains a “process-inject” section with allocator “NtMapViewOfSection” and execution methods including CreateThread, NtQueueApcThread-s, CreateRemoteThread, and RtlCreateUserThread.
The process-injection execute configuration includes “CreateRemoteThread.”
The process-injection execute configuration includes “CreateThread 'ntdll!RtlUserThreadStart'” and “CreateThread.”
The process-injection execute configuration includes “NtQueueApcThread-s.”
Once inside the network, attackers used known techniques for increasing access and compromising the network, including Living-off-the-Land Binaries (LOLbins) and offensive security tools such as Cobalt Strike, Mimikatz and others.
The function GetCurrentProcessId() is used to get all process id along with ThreadId, the GetSystemTimeAsFileTime() to obtain current time. GetStartupInfoA is used to retrieve the content of the STARTUPINFO structure from when the calling process is created.
GetUserNameA is used to retrieve the name of the user associated with the thread.
The beacon includes a variety of functions like command execution, keylogging, file transfer, SOCKS proxying, privilege escalation, mimikatz, port scanning, and lateral movement.
To retrieve the name of the local computer GetComputerNameA API is used.
The malware extracts the name of the files in the current directory.
«URI и заголовки имитируют легитимные API-эндпоинты ... Accept, Accept-Language, X-Requested-With — как у реального AJAX-запроса».
HttpOpenRequestA is used to create an HTTP POST request handle. HttpOpenRequestA API is used to send the request to an HTTP server. The malware queries the server to determine the amount of data available using the InternetQueryDataAvailable API.
“The URIs /ga.js and /submit.php?id=* can be linked to a Cobalt Strike default beaconing profile… The same day these payloads were uploaded to VirusTotal, Sekoia.io provided corroborating evidence linking the IP address 92.39.211[.]142 to a Cobalt Strike C2 server.”
The beacon includes a variety of functions like command execution, keylogging, file transfer, SOCKS proxying, privilege escalation, mimikatz, port scanning, and lateral movement.
«Каналы управления — тактику Command and Control: External Proxy (T1090.002)»; «CDN или коммерческий reverse proxy ... принимает трафик от имплантов».
«Multi-hop Proxy (T1090.003)»; «между имплантом и тимсервером — минимум два слоя redirector'ов».
3,562 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cobalt Strike beacon payload used for command-and-control and post-compromise operations; its deployment was reportedly blocked in the described intrusion.
Dual-use adversary-emulation framework whose Beacon payload provides command-and-control and post-compromise capability.
Имплант Cobalt Strike, загружаемый GOSHELL для удалённого управления через HTTP/S.
Cobalt Strike is mentioned solely because Miraak can load and execute Cobalt Strike-compatible BOF modules through an emulated Beacon API; the content explicitly states Miraak is not a Cobalt Strike Beacon.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.