Cobalt Strike
MITRE ATT&CK: S0154 View on attack.mitre.org
Aliases: Agentemis, BEACON, CobaltStrike, cobeacon, Cobalt Strike
- First seen
- 2012-06-04 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- linux, macos, windows
- Related IoCs
- 148535 (114580 malicious)
- Last IoC activity
- 2026-09-02 04:29:00
- Profile updated
- 2026-07-07 15:46:33
Targeted industries: defense-and-aerospace financial-services government-and-public-sector healthcare-and-pharmaceutical technology-and-telecommunications
Context
Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system. In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.
Recent IoC activity
115,217 malicious indicators in Maltiverse are attributed to Cobalt Strike (S0154). The 20 most recently updated:
Detection coverage
- 144 YARA rules
- 856 Sigma rules
Malware & tools used
- JavaScript (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Native API (attack-pattern)
- Pass the Hash (attack-pattern)
- Domain Accounts (attack-pattern)
- Indicator Removal from Tools (attack-pattern)
- Bypass User Account Control (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Service Execution (attack-pattern)
- Data from Local System (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Keylogging (attack-pattern)
- BITS Jobs (attack-pattern)
- Process Hollowing (attack-pattern)
- Software Discovery (attack-pattern)
- Local Accounts (attack-pattern)
- Internal Proxy (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
- Screen Capture (attack-pattern)
- Process Argument Spoofing (attack-pattern)
- Modify Registry (attack-pattern)
- Domain Groups (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Protocol or Service Impersonation (attack-pattern)
- Parent PID Spoofing (attack-pattern)
Used by threat actors
- APT41 DUST (campaign)
- C0017 (campaign)
- C0021 (campaign)
- C0018 (campaign)
- SolarWinds Compromise (campaign)
- TA577 (threat-actor)
- Chamelgang (threat-actor)
- Karakurt (threat-actor)
- RedGolf (threat-actor)
- Threat Group-3390 (threat-actor)
- Cobalt Group (threat-actor)
- Mustard Tempest (threat-actor)
- Wizard Spider (threat-actor)
- Sandworm Team (threat-actor)
- Cinnamon Tempest (threat-actor)
- Indrik Spider (threat-actor)
- Mustang Panda (threat-actor)
- Aquatic Panda (threat-actor)
- Storm-0501 (threat-actor)
- Storm-1811 (threat-actor)
- APT32 (threat-actor)
- TA505 (threat-actor)
- APT29 (threat-actor)
- APT19 (threat-actor)
- APT41 (threat-actor)
Exploited vulnerabilities
- CVE-2020-10189 (vulnerability)
- CVE-2021-40444 (vulnerability)
- CVE-2022-47966 (vulnerability)
- CVE-2024-30051 (vulnerability)
Detection rules
- TRELLIX_ARC_MALW_Cobaltrike (yara-rule)
- ARKBIRD_SOLG_APT_Chimera_Sept_2020_1 (yara-rule)
- ARKBIRD_SOLG_MAL_Cobaltstrike_Oct_2021_1 (yara-rule)
- ARKBIRD_SOLG_MAL_Beacon_Vermilion_Strike_Sep_2021_1 (yara-rule)
- VOLEXITY_Apt_Malware_Win_Flipflop_Ldr (yara-rule)
- VOLEXITY_Malware_Win_Cobaltstrike_D (yara-rule)
- EMBEERESEARCH_Win_Cobalt_Sleep_Encrypt (yara-rule)
- EMBEERESEARCH_Win_Cobalt_Strike_Loader_Shellcode_Jun_2023 (yara-rule)
- EMBEERESEARCH_Win_Cobaltstrike_Pipe_Strings_Nov_2023 (yara-rule)
- AVASTTI_Cobaltstrike_Raw_Payload_Dns_Stager_X86 (yara-rule)
- AVASTTI_Cobaltstrike_Raw_Payload_Smb_Stager_X86 (yara-rule)
- AVASTTI_Cobaltstrike_Raw_Payload_Tcp_Bind_X86 (yara-rule)
- AVASTTI_Cobaltstrike_Raw_Payload_Tcp_Bind_X64 (yara-rule)
- AVASTTI_Cobaltstrike_Raw_Payload_Tcp_Reverse_X86 (yara-rule)
- AVASTTI_Cobaltstrike_Raw_Payload_Tcp_Reverse_X64 (yara-rule)
- AVASTTI_Cobaltstrike_Raw_Payload_Http_Stager_X86 (yara-rule)
- AVASTTI_Cobaltstrike_Raw_Payload_Http_Stager_X64 (yara-rule)
- AVASTTI_Cobaltstrike_Raw_Payload_Https_Stager_X86 (yara-rule)
- AVASTTI_Cobaltstrike_Raw_Payload_Https_Stager_X64 (yara-rule)
- AVASTTI_Cobaltstrike_Raw_Payload_Dns_Stager_X86_Utf16 (yara-rule)
- AVASTTI_Cobaltstrike_Raw_Payload_Smb_Stager_X86_Utf16 (yara-rule)
- AVASTTI_Cobaltstrike_Raw_Payload_Tcp_Bind_X86_Utf16 (yara-rule)
- AVASTTI_Cobaltstrike_Raw_Payload_Tcp_Bind_X64_Utf16 (yara-rule)
- AVASTTI_Cobaltstrike_Raw_Payload_Tcp_Reverse_X86_Utf16 (yara-rule)
- AVASTTI_Cobaltstrike_Raw_Payload_Tcp_Reverse_X64_Utf16 (yara-rule)
Reports & references
- Broadcom/Symantec — Grayling Taiwan Cyber Attacks (report)
- Mandiant — Phished At The Request Of Counsel (report)
- youtube.com — Watch (report)
- secureworks.com — Bronze Riverside (report)
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- pylos.co — Cozybear In From The Cold (report)
- secureworks.com — Gold Niagara (report)
- secureworks.com — Tin Woodlawn (report)
- volexity.com — Oceanlotus Extending Cyber Espionage Operations Through Fake Websites (report)
- Microsoft — Threat Actor Leverages Coin Miner Techniques To Stay Under The Radar Heres How To Spot Them (report)
- secureworks.com — Gold Kingswood (report)
- secureworks.com — Bronze Mohawk (report)
- Palo Alto Unit 42 — Obscureserpens (report)
- pwc.com — Yir Cyber Threats Annex Download (report)
- secureworks.com — Bronze President (report)
- pwc.co.uk — Cyber Threats 2019 Retrospect (report)
- strapi.eurepoc.eu — Eu Repo C Apt Profile Conti Wizard Spider Dc2A733E18 (report)
- prodaft.com — Wizardspider Tlpwhite V.1.4 (report)
- slideshare.net — Cb19 Cyber Threat Landscape In Japan Revealing Threat In The Shadow By Chi En Shen Ashley Oleg Bondarenko (report)
- MITRE ATT&CK — G0096 (report)
- CrowdStrike — Report2021Gtr (report)
- secureworks.com — Gold Drake (report)
- Mandiant — Kegtap And Singlemalt With A Ransomware Chaser (report)
- i.blackhat.com — Us 20 Chen Operation Chimera Apt Operation Targets Semiconductor Vendors (report)
- wired.com — Chinese Hackers Taiwan Semiconductor Industry Skeleton Key (report)