Critical severity Famous Malware

Cobalt Strike

A legitimate penetration-testing tool that became the most common post-exploitation framework in crime.

Overview

Cobalt Strike provides beacons, malleable command-and-control profiles, lateral movement helpers and privilege escalation, all designed to blend into normal traffic.\nStolen licences mean cracked copies run on criminal infrastructure daily.\nBecause the same binary is used by defenders and attackers, detection rests on configuration fingerprints and behavioural anomalies rather than the file itself.

Indicators of Compromise

Signals that suggest this is present on a system.

  • Named-pipe SMB beacons
  • Sleep-masked beacon traffic with jitter
  • High-entropy HTTPS requests to a single URI pattern

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used