Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Payload is Corkow (Thx Denis Laskov) | CottonCastle : CVE-2014-0515 ... It's the first time i see it in an Exploit Kit ... Flash 13.0.0.182 ... Again Payload is Corkow
Payload is Corkow (Thx Denis Laskov) | CottonCastle : CVE-2013-0634 ... tied to the flash exploit ... Payload is Corkow
CottonCastle : CVE-2013-2465 ... firing code exploiting CVE-2013-2465 to java6u45 ... Exploit for CVE-2013-2465 ... Decoded payload ... Corkow | Payload is Corkow (Thx Denis Laskov)
CottonCastle : CVE-2013-0422 ... Piece of CVE-2013-0422 in CottonCastle ... Decoded Payload ... same familly as previous
2 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Banking malware targeting POS terminals, ATMs, and trading terminals.
Corkow is the payload delivered by the CottonCastle exploit kit across multiple exploit chains, including Flash and Java exploits. The content shows it being downloaded as the final decoded/decrypted payload after exploitation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.