Cobalt Strike is a commercial adversary simulation framework that is widely abused as post-compromise malware, most notably through its Beacon payload. In intrusion reporting it commonly appears as an in-memory implant used for command-and-control, payload staging, and hands-on-keyboard post-exploitation on compromised Windows systems. Although originally designed for red-team operations, it has become a commodity tool across cybercrime and espionage activity and therefore does not provide inherent attribution on its own.
Observed use spans multiple intrusion sets, including suspected China-nexus and India-nexus operations, ransomware intrusions, and exploitation of public-facing enterprise software. Reported campaigns have linked Cobalt Strike activity to espionage targeting Pakistani law enforcement organizations, exploitation chains involving Microsoft Office document attacks such as CVE-2021-40444, and TeamCity compromises that led to deployment of Cobalt Strike beacons alongside other malware. It is also regularly referenced in ransomware operations as a post-exploitation framework used together with administrative tooling and lateral movement utilities.
Beacon payloads associated with Cobalt Strike support covert command-and-control and follow-on operator actions after initial access. Reported behaviors include ingress tool transfer of additional agents or web shells, registry querying and modification to assess or weaken Microsoft Office security settings, and persistence through continued presence in victim environments. Cobalt Strike is also commonly integrated into broader offensive ecosystems and can be paired with loaders, shellcode stagers, or EDR-evasion tooling. Because it is heavily reused by unrelated actors and can be customized through malleable profiles and varied staging methods, defenders typically rely on behavioral and infrastructure analysis rather than family name alone for attribution or detection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
APT29 (Cozy Bear) exploited CVE-2024-27198 in real-world campaigns.
CVE-2021-40444 - пример атаки, где вредоносный документ не содержит макросов... Эксплойт использует уязвимость в MSHTML для удалённого выполнения кода через вредоносный ActiveX-контроль... Включена в каталог CISA KEV (активно эксплуатируется в дикой среде), связана с ransomware-кампаниями... По данным Microsoft MSTIC и Mandiant, CVE-2021-40444 использовалась для доставки Cobalt Strike Beacon | По данным Microsoft MSTIC и Mandiant, CVE-2021-40444 использовалась для доставки Cobalt Strike Beacon в целевых кампаниях.
S-RM has responded to an incident where a threat actor used the recently disclosed critical vulnerability known as React2Shell (CVE-2025-55182) to gain access to a corporate network and deploy ransomware.
Initial access is gained through exploitation of vulnerabilities in Exchange Server (CVE-2021-26855), Openfire (CVE-2023-32315), and GeoServer (CVE-2024-36401), among others.
Initial access is gained through exploitation of vulnerabilities in Exchange Server (CVE-2021-26855), Openfire (CVE-2023-32315), and GeoServer (CVE-2024-36401), among others.
Initial access is gained through exploitation of vulnerabilities in Exchange Server (CVE-2021-26855), Openfire (CVE-2023-32315), and GeoServer (CVE-2024-36401), among others.
Other remote code execution and authentication bypass vulnerabilities weaponized by the threat actor are listed below - Microsoft SharePoint: CVE-2021-27076 ... Upon gaining a foothold, the threat actors establish persistence by deploying web shells to trigger a DLL side-loading chain involving "SystemSettings.exe" (CVE-2021-27076) to deliver SharkLoader ("SystemSettings.dll").
Other remote code execution and authentication bypass vulnerabilities weaponized by the threat actor are listed below - Microsoft Exchange Server: CVE-2022-41082 (aka ProxyNotShell)
Other remote code execution and authentication bypass vulnerabilities weaponized by the threat actor are listed below - Zimbra Collaboration Suite: CVE-2022-27925
Other remote code execution and authentication bypass vulnerabilities weaponized by the threat actor are listed below - Apache Shiro: CVE-2016-4437
Other remote code execution and authentication bypass vulnerabilities weaponized by the threat actor are listed below - F5 BIG-IP: CVE-2023-46747
Other remote code execution and authentication bypass vulnerabilities weaponized by the threat actor are listed below - Hikvision Products: CVE-2021-36260
Other remote code execution and authentication bypass vulnerabilities weaponized by the threat actor are listed below - Fortinet FortiOS: CVE-2022-40684
Other remote code execution and authentication bypass vulnerabilities weaponized by the threat actor are listed below - Cisco IOS XE Web UI: CVE-2023-20198
Other remote code execution and authentication bypass vulnerabilities weaponized by the threat actor are listed below - Fortinet FortiOS: CVE-2024-21762
Member-only story Follina (CVE-2022–30190) & Cobalt Strike C2 -Simple Analysis ... Twitter Intel Initial Access Follina Exploit CVE-2022–30190
Infection sequences start with the exploitation of known security flaws in public-facing ... Progress Telerik UI (CVE-2019-18935) ... servers to drop web shells and deliver Cobalt Strike for lateral movement. | Infection sequences start with the exploitation of known security flaws in public-facing Fortinet (CVE-2022-39952 and CVE-2022-40684), GitLab (CVE-2021-22205), Microsoft Exchange Server (ProxyShell), Progress Telerik UI (CVE-2019-18935), and Zimbra (CVE-2019-9621 and CVE-2019-9670) servers to drop web shells and deliver Cobalt Strike for lateral movement.
Infection sequences start with the exploitation of known security flaws in public-facing ... Zimbra (CVE-2019-9621 and CVE-2019-9670) servers to drop web shells and deliver Cobalt Strike for lateral movement. | Infection sequences start with the exploitation of known security flaws in public-facing Fortinet (CVE-2022-39952 and CVE-2022-40684), GitLab (CVE-2021-22205), Microsoft Exchange Server (ProxyShell), Progress Telerik UI (CVE-2019-18935), and Zimbra (CVE-2019-9621 and CVE-2019-9670) servers to drop web shells and deliver Cobalt Strike for lateral movement.
Infection sequences start with the exploitation of known security flaws in public-facing ... GitLab (CVE-2021-22205) ... servers to drop web shells and deliver Cobalt Strike for lateral movement. | Infection sequences start with the exploitation of known security flaws in public-facing Fortinet (CVE-2022-39952 and CVE-2022-40684), GitLab (CVE-2021-22205), Microsoft Exchange Server (ProxyShell), Progress Telerik UI (CVE-2019-18935), and Zimbra (CVE-2019-9621 and CVE-2019-9670) servers to drop web shells and deliver Cobalt Strike for lateral movement.
Infection sequences start with the exploitation of known security flaws in public-facing ... Microsoft Exchange Server (ProxyShell) ... servers to drop web shells and deliver Cobalt Strike for lateral movement. | Infection sequences start with the exploitation of known security flaws in public-facing Fortinet (CVE-2022-39952 and CVE-2022-40684), GitLab (CVE-2021-22205), Microsoft Exchange Server (ProxyShell), Progress Telerik UI (CVE-2019-18935), and Zimbra (CVE-2019-9621 and CVE-2019-9670) servers to drop web shells and deliver Cobalt Strike for lateral movement.
50 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Shellcode: PEB walk + export hash resolver + 54 internal functions ... Second-stage payload (likely a follow-on PE or Cobalt Strike beacon)
In this particular campaign, APT29 used VaporRage to distribute Cobalt Strike beacons to further establish a foothold within the environment.
The tool has been spotted delivering Cobalt Strike Beacon, a well known post exploitation framework, onto compromised machines.
Beyond the custom backdoor, the Rapid7 researchers observed the deployment of Cobalt Strike and Metasploit frameworks, noting that the campaign was characterized by highly surgical targeting of government, telecommunications, and financial sectors rather than a broad, indiscriminate infection of the general user base.
they executed a PowerShell command to download additional payloads from a remote location using a Cobalt Strike Beacon, maintaining persistence throughout this process using SystemBC.
TA577, are a Russia-based threat group that have been reported to deliver payloads including Qbot, IcedID, SystemBC, SmokeLoader, Ursnif, and Cobalt Strike in ongoing phishing campaigns since 2020.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
These hashes empower server clustering, identification of unique and similar servers, and the pursuit of malicious actors with heightened confidence.
HTTP-Basma’s algorithm's core idea centers on sending 8 specially crafted HTTP requests with varying requirements to elicit different responses from the server.
The researchers grouped the intrusions into four clusters based on the malware and infrastructure involved: PlugX, ShadowPad, Cobalt Strike, and Remcos.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
180秒スリープした後に、外部サーバに HTTP GET でアクセスしダウンロードしたコードを新たに起動した Explorer.exeに インジェクションする。 (Process Hollowing)
Классические process injection техники - DLL Injection (T1055.001)... Цепочка VirtualAllocEx -> WriteProcessMemory -> CreateRemoteThread с адресом LoadLibrary
Since encoded commands are often long, set a threshold (e.g., 1000 characters) to flag suspiciously long commands.
180秒スリープした後に、外部サーバに HTTP GET でアクセスしダウンロードしたコードを新たに起動した Explorer.exeに インジェクションする。 (Process Hollowing)
Классические process injection техники - DLL Injection (T1055.001)... Цепочка VirtualAllocEx -> WriteProcessMemory -> CreateRemoteThread с адресом LoadLibrary
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
During this time period, multiple rounds of enumeration and lateral movement occurred using Cobalt Strike.
Make the malleable C2 parser robust to real Cobalt Strike profiles and honour space-separated URI lists.
Between Jan–Jun 2026 botnet C&C servers observed decreased -30% to 14,952. Sliver overtook Cobalt Strike for the #1 spot (+58%). Meanwhile .cn botnet C&C domains surged +771%...
1,087 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cobalt Strike14
An offensive tool used by one or more of the observed threat clusters during the sustained cyber espionage activity.
Mentioned as an example of traditional, reusable attacker tooling contrasted with bespoke AI-generated scripts.
Related articles CrossC2 Expanding Cobalt Strike Beacon to Cross-Platform Attacks
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.