A Multi-Method Approach to Identifying Rogue Cobalt Strike ServersRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Ransomware57
Identifying Rogue Cobalt Strike Servers: A Recorded Future ApproachRecorded Future·Aug 12, 00:00 UTC · Aug 12, 2025Vulnerability42
Blowing Cobalt Strike Out of the Water With Memory AnalysisPalo Alto Unit 42·Jun 5, 17:24 UTC · Jun 5, 2024Ransomware57
Attackers use domain fronting technique to target Myanmar with Cobalt StrikeCisco Talos·Nov 16, 12:00 UTC · Nov 16, 2021Ransomware57
How to Detect Cobalt Strike: An Inside Look at the Popular Commercial PostRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Ransomware57
New campaign uses government, union-themed lures to deliver Cobalt Strike beaconsCisco Talos·Sep 28, 12:12 UTC · Sep 28, 2022Threat actorCVE-2017-019960
Cobalt Partner Program offers new opportunities for partnersHelp Net Security·Mar 15, 00:00 UTC · Mar 15, 2021Vulnerability30
APT41 likely compromised Taiwanese government-affiliated research institute with ShadowPad and Cobalt StrikeCisco Talos·Aug 1, 12:00 UTC · Aug 1, 2024Threat actorCVE-2018-0824160
Microsoft leads effort to disrupt illicit use of Cobalt Strike, a dangerous hacking tool in the wrong handsCyberScoop·Apr 6, 16:00 UTC · Apr 6, 2023Ransomware in the wild60
New Snort, ClamAV coverage strikes back against Cobalt StrikeCisco Talos·Sep 21, 04:01 UTC · Sep 21, 2020Ransomware157
The Cobalt Hacking crew is still active even after the arrest of its leaderSecurity Affairs·May 29, 05:17 UTC · May 29, 2018Ransomware60
Live Cybersecurity Webinar — Deconstructing Cobalt StrikeThe Hacker News·Jun 11, 08:17 UTC · Jun 11, 2021Vulnerability30
CobaltSpam tool can flood Cobalt Strike malware serversThe Record·Dec 13, 00:00 UTC · Dec 13, 2022Malware42
Cisco Talos Advisory on Adversaries Targeting the Healthcare and Public Health SectorCisco Talos·Oct 30, 21:30 UTC · Oct 30, 2020Advisory42
A Cobalt Strike flaw exposed attackers' infrastructureSecurity Affairs·Mar 3, 13:17 UTC · Mar 3, 2019Vulnerability30
New Techniques to Uncover and Attribute Cobalt Gang Commodity Builders and Infrastructure RevealedPalo Alto Unit 42·Nov 5, 08:54 UTC · Nov 5, 2018VulnerabilityCVE-2017-019935
Cobalt cybercrime gang targets Russian and Romanian banksSecurity Affairs·Sep 1, 09:34 UTC · Sep 1, 2018Malware42
Operation Morpheus took down 593 Cobalt Strike servers used by threat actorsSecurity Affairs·Jul 3, 18:24 UTC · Jul 3, 2024Threat actor160
Cobalt crime gang is using again CobInt in attacks on former soviet statesSecurity Affairs·Sep 13, 08:01 UTC · Sep 13, 2018VulnerabilityCVE-2017-8570CVE-2017-11882CVE-2018-0802+1 CVEs47
Cobalt adds Autonomous Pentest to scale application security testingHelp Net Security·Jul 23, 00:00 UTC · Jul 23, 2026Threat actor60
China-Nexus TAG-112 Compromises Tibetan Websites to Distribute Cobalt StrikeRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Vulnerability42
Unmasking the new persistent attacks on JapanCisco Talos·Mar 6, 11:00 UTC · Mar 6, 2025VulnerabilityCVE-2024-4577160
Manjusaka: A Chinese sibling of Sliver and Cobalt StrikeCisco Talos·Aug 2, 12:00 UTC · Aug 2, 2022Malware55
Cobalt names Eric Brinkman as Chief Product OfficerHelp Net Security·Feb 26, 00:00 UTC · Feb 26, 2021Industry55
Microsoft aims at stopping cybercriminals from using cracked copies of Cobalt StrikeSecurity Affairs·Apr 7, 10:38 UTC · Apr 7, 2023Ransomware60
'Cobalt Group' launches new campaign against banks in Romania, RussiaCyberScoop·Aug 30, 22:43 UTC · Aug 30, 2018Threat actor in the wild60
Cobalt adds continuous pentesting AI capabilities to scale offensive security and real-world riskHelp Net Security·Mar 25, 10:01 UTC · Mar 25, 2026Vulnerability55
Number of Unauthorized Cobalt Strike Copies Plummets 80%Infosecurity Magazine·Mar 10, 09:30 UTC · Mar 10, 2025Threat actor45
HelpSystems Patch Falls Short, RCE Vulnerability in Cobalt Strike RemainsInfosecurity Magazine·Oct 18, 17:00 UTC · Oct 18, 2022VulnerabilityCVE-2022-42948CVE-2022-3919747
Hackers Found Using CrossC2 to Expand Cobalt Strike Beacon’s Reach to Linux and macOSThe Hacker News·Aug 15, 00:00 UTC · Aug 15, 2025Ransomware57
SOC files: an APT41 attack on government IT services in AfricaKaspersky Securelist·Jul 21, 08:00 UTC · Jul 21, 2025Threat actor60
Malicious use of Cobalt Strike down 80% after crackdown, Fortra saysThe Record·Mar 7, 19:06 UTC · Mar 7, 2025Ransomware57
UK’s NCA Leads Major Cobalt Strike TakedownInfosecurity Magazine·Jul 4, 09:30 UTC · Jul 4, 2024Ransomware57
Microsoft Takes Legal Action to Disrupt Cybercriminals' Illegal Use of Cobalt Strike ToolThe Hacker News·Apr 8, 04:44 UTC · Apr 8, 2023Ransomware57
Threat actor ports Cobalt Strike beacon to Linux, uses it in attacksThe Record·Dec 13, 00:00 UTC · Dec 13, 2022Threat actor57
Google seeks to make Cobalt Strike useless to attackersHelp Net Security·Nov 21, 00:00 UTC · Nov 21, 2022Threat actor45
Experts found a link between a Magecart group and Cobalt GroupSecurity Affairs·Oct 8, 14:14 UTC · Oct 8, 2019VulnerabilityCVE-2017-019947
Bug in Cobalt Strike pentesting tool used to identify malicious serversHelp Net Security·Mar 1, 00:00 UTC · Mar 1, 2019Malware42
Additional Entities Targeted by DarkSide Affiliate, TAG-21; Links to WellMess and Sliver InfrastructureRecorded Future·Jul 15, 00:00 UTC · Jul 15, 2025Ransomware57