Security researchers detailed multiple ways to identify and decrypt Cobalt Strike command-and-control traffic, including the use of known private RSA keys recovered from cracked or rogue distributions. NVISO reported finding six unique RSA key pairs inside leaked Cobalt Strike ZIP packages and said more than 25% of over 1,500 fingerprinted Internet-facing servers used one of two widely reused key pairs, allowing analysts to identify rogue beacons and in some cases decrypt beacon metadata and full C2 communications with tools such as 1768.py.
The research also showed how defenders can recover and decode traffic protected by malleable C2 transformations and sleep-masked beacon memory. Analysts can reverse custom transforms such as dropped bytes, Base64 URL decoding, and XOR decoding to recover encrypted payloads, then extract AES and HMAC keys from process memory—even when beacon memory is obfuscated during sleep—using tools including cs-analyze-processdump.py, cs-extract-key.py, and cs-parse-traffic.py to decrypt HTTP(S) and DNS beacon traffic.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
NVISO published an overview of its multi-part research series on analyzing and decrypting Cobalt Strike traffic, covering private-key decryption, memory-based key extraction, obfuscated traffic, DNS traffic, and beacon memory dumping. The overview noted that the beta tool cs-parse-http-traffic.py had been replaced by cs-parse-traffic.py, which supports both HTTP(S) and DNS traffic.
NVISO published research showing how to reverse malleable C2 data transforms, recover encrypted Cobalt Strike traffic, and handle sleep-mask-obfuscated process memory. The article also described using cs-analyze-processdump.py and cs-extract-key.py to recover cryptographic keys from decoded memory dumps.
NVISO published research demonstrating how to extract a Cobalt Strike beacon from a packet capture, decode its configuration, decrypt beacon metadata with a known leaked private key, and use the recovered raw key to decrypt HTTP C2 traffic. The analysis revealed operator tasking including a sleep change to 100 ms with 90% jitter, a likely directory-listing command, and a later process-listing command.
The recovered private key information was incorporated into Didier Stevens' 1768.py tool so analysts could identify rogue Cobalt Strike beacons and, when possible, decrypt beacon metadata and C2 traffic. The article presenting this work was published on October 21, 2021.
NVISO researchers searched VirusTotal, found 10 cracked Cobalt Strike ZIP packages containing .cobaltstrike.beacon_keys files, and extracted six unique RSA key pairs. They also observed that many Internet-facing Cobalt Strike servers reused the same public keys, with more than 25% of 1,500+ fingerprinted servers using one of two prevalent key pairs.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
6 references tracked. Mallory keeps watching after this page renders.
research.nccgroup.com
Open sourceblog.nviso.eu
Open sourceblog.nviso.eu
Open sourcegithub.com
Open sourceblog.nviso.eu
Open sourceblog.nviso.eu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.