Cobalt Strike Beacon is the payload component of the Cobalt Strike adversary simulation framework and is widely used as an in-memory backdoor by both red teams and threat actors. It supports command-and-control over multiple transports including HTTP, HTTPS, DNS, SMB, and TCP, and is commonly used after initial compromise to maintain access, execute commands, move laterally, escalate privileges, dump credentials, and stage additional tooling or payloads. Beacon is frequently deployed reflectively or loaded directly into memory by droppers, loaders, or shellcode launchers, and it is often paired with malleable C2 profiles to blend network traffic with legitimate services.
Beacon has been observed across a broad range of intrusion sets spanning espionage and financially motivated operations. Reported users include APT29, APT32, APT40, APT41, UNC2198, UNC2447, UNC2165, and other clusters that incorporated Beacon alongside custom malware, web shells, credential theft tools, and ransomware workflows. In these operations, Beacon has served as a first-stage or follow-on backdoor for persistence and operator control, including use as SMB Beacon for lateral movement and internal pivoting. It has also been delivered by malware such as DUSTPAN and memory-only droppers, and has been adapted for DLL proxying and sideload-style execution in Windows environments.
Beacon primarily targets Windows in the supplied reporting, though Beacon-style implants and related frameworks are also described on Linux and macOS in adjacent tooling contexts. In observed intrusions, Beacon has supported post-exploitation objectives against government, diplomatic, defense, maritime, technology, hospitality, consumer products, telecommunications, and other enterprise sectors. Its prevalence, flexibility, and support for in-memory execution have made it one of the most recognizable and operationally significant post-compromise implants in modern intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
First-stage backdoors such as AIRBREAK, FRESHAIR, and BEACON are used before downloading other payloads.
First-stage backdoors such as AIRBREAK, FRESHAIR, and BEACON are used before downloading other payloads.
First-stage backdoors such as AIRBREAK, FRESHAIR, and BEACON are used before downloading other payloads.
First-stage backdoors such as AIRBREAK, FRESHAIR, and BEACON are used before downloading other payloads.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Beacon This red team tool is based on the CobaltStrike beacon. A beacon is a CobaltStrike payload used by adversaries for several goals, such as persistence, execution, privilege escalation, credential dumping, lateral movement, and Command and Control (C2) communication over HTTP, HTTPS, DNS, SMB, and TCP protocols.
The DUSTPAN samples were configured to load BEACON payloads into memory that were encrypted using chacha20. The BEACON payloads, once executed, communicated using either self-managed infrastructure hosted behind Cloudflare or utilized Cloudflare Workers as their command-and-control (C2) channels.
UNC2165 also reportedly has used Beacon payloads and a command-and-control (C2) server other information security firms have linked to suspected Evil Corp activity...
"GOVERSHELL has already spawned five variants, including the most recent Beacon malware that could enable PowerShell command execution."
UNC2447 uses the Cobalt Strike BEACON HTTPSSTAGER implant for persistence to communicate with command-and-control (C2) servers over HTTPS...
UNC2198 has used Cobalt Strike BEACON, Metasploit METERPRETER, KOADIC, and PowerShell EMPIRE offensive security tools during this phase as well.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
The beacon includes a variety of functions like command execution, keylogging, file transfer, SOCKS proxying, privilege escalation, mimikatz, port scanning, and lateral movement.
DKMC is a tool that generates obfuscated shellcode that is stored inside of polyglot images. The image is 100% valid and also 100% valid shellcode.
Usually, the Cobalt Strike beacon injects itself into any running process to evade detection and stay persistent.
The function GetCurrentProcessId() is used to get all process id along with ThreadId, the GetSystemTimeAsFileTime() to obtain current time. GetStartupInfoA is used to retrieve the content of the STARTUPINFO structure from when the calling process is created.
GetUserNameA is used to retrieve the name of the user associated with the thread.
The beacon includes a variety of functions like command execution, keylogging, file transfer, SOCKS proxying, privilege escalation, mimikatz, port scanning, and lateral movement.
To retrieve the name of the local computer GetComputerNameA API is used.
The malware extracts the name of the files in the current directory.
The most visible differences between a default profile and a custom profile Beacon configuration are the number of instructions and data transformations, as well as the HTTP parameters used.
HttpOpenRequestA is used to create an HTTP POST request handle. HttpOpenRequestA API is used to send the request to an HTTP server. The malware queries the server to determine the amount of data available using the InternetQueryDataAvailable API.
There are several HTTP transactions of GET and POST requests and responses.
dns-beacon: After Cobalt Strike v4.3, DNS options became part of the dns-beacon transaction. This transaction modifies the DNS C2 communication.
The beacon includes a variety of functions like command execution, keylogging, file transfer, SOCKS proxying, privilege escalation, mimikatz, port scanning, and lateral movement.
With the Cobalt Strike payloads injected, the cybercriminals can then further traverse the target environment (move laterally) or pull-down additional tools and malware.
Figure 14 shows extracted configuration metadata for a custom profile Beacon... includes encoding types... Build Metadata: [7:Metadata, 11,5:tmp ] NETBIOS uppercase Parameter tmp
76 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The content references a named payload 'Beacon1.0.0', indicating a Beacon backdoor payload associated with the listed executables, script, domains, and IP infrastructure. No further behavioral detail is provided in the content.
Cross-platform C++ implant used by AdaptixC2 that supports BOF execution and multiple callback transports including HTTP/S, DNS, SMB named pipes, and TCP. It checks in with operator-controlled listeners for tasking and can execute commands and payloads in-memory.
A GOVERSHELL variant described as enabling PowerShell command execution.
BEACON is the main payload of Cobalt Strike, used for post-exploitation, command and control, and lateral movement. It is widely abused by threat actors for advanced attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.