Cobalt Strike

MITRE ATT&CK: S0154 View on attack.mitre.org

Aliases: Agentemis, BEACON, CobaltStrike, cobeacon, Cobalt Strike

First seen
2012-06-04 00:00:00
Malware type
rat
Family
Malware family
Operating systems
linux, macos, windows
Related IoCs
148535 (114580 malicious)
Last IoC activity
2026-09-02 04:29:00
Profile updated
2026-07-07 15:46:33

Targeted industries: defense-and-aerospace financial-services government-and-public-sector healthcare-and-pharmaceutical technology-and-telecommunications

Context

Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system. In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.

Recent IoC activity

115,217 malicious indicators in Maltiverse are attributed to Cobalt Strike (S0154). The 20 most recently updated:

Detection coverage

  • 144 YARA rules
  • 856 Sigma rules

Malware & tools used

  • JavaScript (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)
  • Native API (attack-pattern)
  • Pass the Hash (attack-pattern)
  • Domain Accounts (attack-pattern)
  • Indicator Removal from Tools (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Service Execution (attack-pattern)
  • Data from Local System (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • Keylogging (attack-pattern)
  • BITS Jobs (attack-pattern)
  • Process Hollowing (attack-pattern)
  • Software Discovery (attack-pattern)
  • Local Accounts (attack-pattern)
  • Internal Proxy (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Screen Capture (attack-pattern)
  • Process Argument Spoofing (attack-pattern)
  • Modify Registry (attack-pattern)
  • Domain Groups (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Protocol or Service Impersonation (attack-pattern)
  • Parent PID Spoofing (attack-pattern)

Used by threat actors

Exploited vulnerabilities

  • CVE-2020-10189 (vulnerability)
  • CVE-2021-40444 (vulnerability)
  • CVE-2022-47966 (vulnerability)
  • CVE-2024-30051 (vulnerability)

Detection rules

  • TRELLIX_ARC_MALW_Cobaltrike (yara-rule)
  • ARKBIRD_SOLG_APT_Chimera_Sept_2020_1 (yara-rule)
  • ARKBIRD_SOLG_MAL_Cobaltstrike_Oct_2021_1 (yara-rule)
  • ARKBIRD_SOLG_MAL_Beacon_Vermilion_Strike_Sep_2021_1 (yara-rule)
  • VOLEXITY_Apt_Malware_Win_Flipflop_Ldr (yara-rule)
  • VOLEXITY_Malware_Win_Cobaltstrike_D (yara-rule)
  • EMBEERESEARCH_Win_Cobalt_Sleep_Encrypt (yara-rule)
  • EMBEERESEARCH_Win_Cobalt_Strike_Loader_Shellcode_Jun_2023 (yara-rule)
  • EMBEERESEARCH_Win_Cobaltstrike_Pipe_Strings_Nov_2023 (yara-rule)
  • AVASTTI_Cobaltstrike_Raw_Payload_Dns_Stager_X86 (yara-rule)
  • AVASTTI_Cobaltstrike_Raw_Payload_Smb_Stager_X86 (yara-rule)
  • AVASTTI_Cobaltstrike_Raw_Payload_Tcp_Bind_X86 (yara-rule)
  • AVASTTI_Cobaltstrike_Raw_Payload_Tcp_Bind_X64 (yara-rule)
  • AVASTTI_Cobaltstrike_Raw_Payload_Tcp_Reverse_X86 (yara-rule)
  • AVASTTI_Cobaltstrike_Raw_Payload_Tcp_Reverse_X64 (yara-rule)
  • AVASTTI_Cobaltstrike_Raw_Payload_Http_Stager_X86 (yara-rule)
  • AVASTTI_Cobaltstrike_Raw_Payload_Http_Stager_X64 (yara-rule)
  • AVASTTI_Cobaltstrike_Raw_Payload_Https_Stager_X86 (yara-rule)
  • AVASTTI_Cobaltstrike_Raw_Payload_Https_Stager_X64 (yara-rule)
  • AVASTTI_Cobaltstrike_Raw_Payload_Dns_Stager_X86_Utf16 (yara-rule)
  • AVASTTI_Cobaltstrike_Raw_Payload_Smb_Stager_X86_Utf16 (yara-rule)
  • AVASTTI_Cobaltstrike_Raw_Payload_Tcp_Bind_X86_Utf16 (yara-rule)
  • AVASTTI_Cobaltstrike_Raw_Payload_Tcp_Bind_X64_Utf16 (yara-rule)
  • AVASTTI_Cobaltstrike_Raw_Payload_Tcp_Reverse_X86_Utf16 (yara-rule)
  • AVASTTI_Cobaltstrike_Raw_Payload_Tcp_Reverse_X64_Utf16 (yara-rule)

Reports & references

  • Broadcom/Symantec — Grayling Taiwan Cyber Attacks (report)
  • Mandiant — Phished At The Request Of Counsel (report)
  • youtube.com — Watch (report)
  • secureworks.com — Bronze Riverside (report)
  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • pylos.co — Cozybear In From The Cold (report)
  • secureworks.com — Gold Niagara (report)
  • secureworks.com — Tin Woodlawn (report)
  • volexity.com — Oceanlotus Extending Cyber Espionage Operations Through Fake Websites (report)
  • Microsoft — Threat Actor Leverages Coin Miner Techniques To Stay Under The Radar Heres How To Spot Them (report)
  • secureworks.com — Gold Kingswood (report)
  • secureworks.com — Bronze Mohawk (report)
  • Palo Alto Unit 42 — Obscureserpens (report)
  • pwc.com — Yir Cyber Threats Annex Download (report)
  • secureworks.com — Bronze President (report)
  • pwc.co.uk — Cyber Threats 2019 Retrospect (report)
  • strapi.eurepoc.eu — Eu Repo C Apt Profile Conti Wizard Spider Dc2A733E18 (report)
  • prodaft.com — Wizardspider Tlpwhite V.1.4 (report)
  • slideshare.net — Cb19 Cyber Threat Landscape In Japan Revealing Threat In The Shadow By Chi En Shen Ashley Oleg Bondarenko (report)
  • MITRE ATT&CK — G0096 (report)
  • CrowdStrike — Report2021Gtr (report)
  • secureworks.com — Gold Drake (report)
  • Mandiant — Kegtap And Singlemalt With A Ransomware Chaser (report)
  • i.blackhat.com — Us 20 Chen Operation Chimera Apt Operation Targets Semiconductor Vendors (report)
  • wired.com — Chinese Hackers Taiwan Semiconductor Industry Skeleton Key (report)

External references