Cobeacon is a Cobalt Strike Beacon payload used in both cybercrime and espionage intrusions as a post-compromise command-and-control implant. It has been observed after server-side exploitation and web shell deployment, including in BlackByte ransomware operations where attackers used it after initial access to execute ransomware and support movement through victim networks. It has also been associated with the China-linked espionage cluster Earth Alux, which used COBEACON alongside other custom tooling to maintain command and control, establish persistence, and support credential theft and broader information-theft operations.
The malware functions as a backdoor or remote access implant that enables operators to control compromised systems after intrusion. Reported use cases include maintaining command and control, supporting persistence, and enabling follow-on actions by operators. In ransomware intrusions, it has been repeatedly deployed during internal movement and used as an execution mechanism for later-stage payloads. In espionage activity, it has formed part of a multi-stage toolkit used against government, technology, logistics, manufacturing, telecommunications, IT services, and retail organizations, particularly in the Asia-Pacific and Latin American regions.
Observed delivery has depended on the broader intrusion chain rather than standalone mass distribution. Documented infections include deployment after exploitation of vulnerable internet-facing servers and creation of web shells, with subsequent retrieval and execution using native Windows utilities. High-confidence reporting also links it to web-shell-based initial access used by Earth Alux. The malware is primarily associated with Windows intrusions in the supplied reporting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Exploiting the vulnerable server allows the attacker to create a web shell to the system which is then used to download and drop Cobeacon using Certutil... After the deployment of Cobeacon, it is then used to execute BlackByte ransomware.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Earth Alux employs multiple custom tools including VARGEIT, RAILLOAD, RAILSETTER, and COBEACON to establish persistence, steal credentials, and maintain command and control.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used in multi-stage intrusions attributed to the China-linked actor Earth Alux.
Cobeacon is described as a malware/tool deployed after initial access and used to help execute BlackByte and propagate activity in the victim network.
Penetration testing tool often abused as a backdoor for command and control, lateral movement, and post-exploitation activities.
Custom malware/tool used by Earth Alux for command-and-control and persistent access during espionage operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.