Cobalt Strike is a commercial adversary simulation and post-exploitation framework that is extensively abused by criminal and state-linked threat actors as an intrusion platform. Its Beacon payload is commonly deployed after an initial foothold established by other malware, stolen credentials, exploitation of internet-facing systems, or phishing-delivered loaders. In malicious operations it is used to provide interactive command execution, in-memory payload execution, reconnaissance, credential access support, lateral movement enablement, persistence, and defense evasion.
Observed intrusion chains frequently place Cobalt Strike after loaders or initial backdoors such as Qbot, IcedID, or SharkLoader, or after direct exploitation of exposed enterprise applications and appliances. Operators have launched Beacon through encoded PowerShell, process injection, malicious services, DLL side-loading, and webshell-driven execution. It is regularly paired with administrative tools and LOLBins such as PsExec, WMI, RDP, PowerShell, and remote-management software to expand access across victim environments.
Across reported incidents, Cobalt Strike has been used by ransomware operators including Royal, Quantum, Qilin, INC Ransom, and Medusa, as well as by espionage actors and China-nexus intrusions involving telecom and law-enforcement targets. It has appeared in compromises affecting manufacturing, healthcare, government, telecom, public administration, energy, defense, and software-related organizations. On servers and endpoints, Beacon commonly supports post-compromise operations such as Active Directory enumeration, credential harvesting workflows, remote execution, and staging of follow-on malware or ransomware.
The framework is strongly associated with stealth-oriented tradecraft. Reported deployments include in-memory execution, process injection, peer-to-peer communications, HTTPS-based command and control, scheduled-task or service-based persistence, and use alongside obfuscated PowerShell and other evasion measures. Although Cobalt Strike is legitimate software when used for authorized security testing, its widespread repurposing by threat actors has made Beacon one of the most recognizable and prevalent post-exploitation implants in modern intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
External User Tags #cobaltstrike
In addition, threat actors were observed scanning and exploiting vulnerabilities in various enterprise software and network appliances, including: Joomla CMS – CVE-2023-23752
In addition, threat actors were observed scanning and exploiting vulnerabilities in various enterprise software and network appliances, including: Zimbra Collaboration Suite – CVE-2022-27925
Observed attacks have targeted a range of widely deployed platforms, including: Microsoft SharePoint (e.g. CVE-2021-27076)
Observed attacks have targeted a range of widely deployed platforms, including: GeoServer (e.g. CVE-2024-36401)
In addition, threat actors were observed scanning and exploiting vulnerabilities in various enterprise software and network appliances, including: Jenkins – CVE-2024-23897
In addition, threat actors were observed scanning and exploiting vulnerabilities in various enterprise software and network appliances, including: Microsoft Exchange Server – CVE-2022-41082
In addition, threat actors were observed scanning and exploiting vulnerabilities in various enterprise software and network appliances, including: React Server Components – CVE-2025-55182
In addition, threat actors were observed scanning and exploiting vulnerabilities in various enterprise software and network appliances, including: Fortinet FortiOS – CVE-2022-40684, CVE-2024-21762
Observed attacks have targeted a range of widely deployed platforms, including: Openfire Server (e.g. CVE-2023-32315)
In addition, threat actors were observed scanning and exploiting vulnerabilities in various enterprise software and network appliances, including: F5 BIG-IP – CVE-2023-46747
In addition, threat actors were observed scanning and exploiting vulnerabilities in various enterprise software and network appliances, including: Hikvision products – CVE-2021-36260
Observed attacks have targeted a range of widely deployed platforms, including: Microsoft Exchange Server (e.g. CVE-2021-26855, ProxyLogon)
In addition, threat actors were observed scanning and exploiting vulnerabilities in various enterprise software and network appliances, including: Apache Shiro – CVE-2016-4437
In addition, threat actors were observed scanning and exploiting vulnerabilities in various enterprise software and network appliances, including: Fortinet FortiOS – CVE-2022-40684, CVE-2024-21762
In addition, threat actors were observed scanning and exploiting vulnerabilities in various enterprise software and network appliances, including: Cisco IOS XE Web UI – CVE-2023-20198
APT29 (Cozy Bear) exploited CVE-2024-27198 in real-world campaigns.
CVE-2021-40444 - пример атаки, где вредоносный документ не содержит макросов... Эксплойт использует уязвимость в MSHTML для удалённого выполнения кода через вредоносный ActiveX-контроль... Включена в каталог CISA KEV (активно эксплуатируется в дикой среде), связана с ransomware-кампаниями... По данным Microsoft MSTIC и Mandiant, CVE-2021-40444 использовалась для доставки Cobalt Strike Beacon | По данным Microsoft MSTIC и Mandiant, CVE-2021-40444 использовалась для доставки Cobalt Strike Beacon в целевых кампаниях.
Member-only story Follina (CVE-2022–30190) & Cobalt Strike C2 -Simple Analysis ... Twitter Intel Initial Access Follina Exploit CVE-2022–30190
50 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
По данным BushidoToken, на инфраструктуре BitLaunch систематически обнаруживаются C2-серверы, в первую очередь CobaltStrike.
По данным BushidoToken, на инфраструктуре BitLaunch систематически обнаруживаются C2-серверы, в первую очередь CobaltStrike.
APT29/Nobelium Cobalt Strike C2 setup with custom certificates and redirections ... APT29/Nobelium Cobalt Strike C2 redirector setup
A distinctive characteristic of INC Ransom’s operations is its extensive use of Living-off-the-Land Binaries (LOLBins), Remote Monitoring and Management (RMM) tools, post-exploitation frameworks such as Cobalt Strike, and custom scripts designed to automate ransomware propagation.
На серверах (за пределами сетевых устройств) Salt Typhoon разворачивает бэкдор GhostSpider (по данным Trend Micro, разработан специально для телеком-сетей), руткит Demodex (kernel-mode), Cobalt Strike, а также SnappyBee и HemiGate.
Shellcode: PEB walk + export hash resolver + 54 internal functions ... Second-stage payload (likely a follow-on PE or Cobalt Strike beacon)
36 distinct techniques documented for this family, organized by ATT&CK tactic.
A new point of detail is the use of scheduled tasks to establish persistence and process injection to initiate Cobalt Strike.
The researchers grouped the intrusions into four clusters based on the malware and infrastructure involved: PlugX, ShadowPad, Cobalt Strike, and Remcos.
The attackers used Qbot as the first backdoor and then launched Cobalt Strike through encoded PowerShell commands.
A new point of detail is the use of scheduled tasks to establish persistence and process injection to initiate Cobalt Strike.
After gaining privileged domain accounts, the group used them to move through the network.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
A suspected China-nexus actor planted implants in one of the web applications, which serves both police staff and citizens, weaponizing a tool of Pakistan’s police digitalization against its users.
A new point of detail is the use of scheduled tasks to establish persistence and process injection to initiate Cobalt Strike.
The two tools were also injected into legitimate Windows processes, making malicious activity harder to spot
After gaining privileged domain accounts, the group used them to move through the network.
Cobalt Strike was installed as a Windows service on several systems.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
Two hours following the IcedID execution, the attackers utilized Cobalt Strike ... continuing to gather system information, however, this time from an AdFind bat script.
The operators also used built-in Windows utilities to list users
Following initial access, attackers typically perform: System and network reconnaissance
used built-in Windows utilities to list users, groups, domain trusts, and available network shares.
Following initial access, attackers typically perform: System and network reconnaissance
Its analysis of command-and-control netflow data revealed four tooling clusters converging on this victim class: PlugX, ShadowPad, Cobalt Strike, and Remcos.
Ingress Tool Transfer (T1105). Загрузка C2-агента (Cobalt Strike beacon, Sliver implant) или web shell для устойчивого доступа.
1,088 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this malware family.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.