A Multi-Method Approach to Identifying Rogue Cobalt Strike ServersRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Ransomware57
Identifying Rogue Cobalt Strike Servers: A Recorded Future ApproachRecorded Future·Aug 12, 00:00 UTC · Aug 12, 2025Vulnerability42
Blowing Cobalt Strike Out of the Water With Memory AnalysisPalo Alto Unit 42·Jun 5, 17:24 UTC · Jun 5, 2024Ransomware57
Attackers use domain fronting technique to target Myanmar with Cobalt StrikeCisco Talos·Nov 16, 12:00 UTC · Nov 16, 2021Ransomware57
How to Detect Cobalt Strike: An Inside Look at the Popular Commercial PostRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Ransomware57
New campaign uses government, union-themed lures to deliver Cobalt Strike beaconsCisco Talos·Sep 28, 12:12 UTC · Sep 28, 2022Threat actorCVE-2017-019960
APT41 likely compromised Taiwanese government-affiliated research institute with ShadowPad and Cobalt StrikeCisco Talos·Aug 1, 12:00 UTC · Aug 1, 2024Threat actorCVE-2018-0824160
New Snort, ClamAV coverage strikes back against Cobalt StrikeCisco Talos·Sep 21, 04:01 UTC · Sep 21, 2020Ransomware157
CobaltSpam tool can flood Cobalt Strike malware serversThe Record·Dec 13, 00:00 UTC · Dec 13, 2022Malware42
Cisco Talos Advisory on Adversaries Targeting the Healthcare and Public Health SectorCisco Talos·Oct 30, 21:30 UTC · Oct 30, 2020Advisory42
Cobalt cybercrime gang targets Russian and Romanian banksSecurity Affairs·Sep 1, 09:34 UTC · Sep 1, 2018Malware42
Cobalt crime gang is using again CobInt in attacks on former soviet statesSecurity Affairs·Sep 13, 08:01 UTC · Sep 13, 2018VulnerabilityCVE-2017-8570CVE-2017-11882CVE-2018-0802+1 CVEs47
China-Nexus TAG-112 Compromises Tibetan Websites to Distribute Cobalt StrikeRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Vulnerability42
HelpSystems Patch Falls Short, RCE Vulnerability in Cobalt Strike RemainsInfosecurity Magazine·Oct 18, 17:00 UTC · Oct 18, 2022VulnerabilityCVE-2022-42948CVE-2022-3919747
Hackers Found Using CrossC2 to Expand Cobalt Strike Beacon’s Reach to Linux and macOSThe Hacker News·Aug 15, 00:00 UTC · Aug 15, 2025Ransomware57
Malicious use of Cobalt Strike down 80% after crackdown, Fortra saysThe Record·Mar 7, 19:06 UTC · Mar 7, 2025Ransomware57
UK’s NCA Leads Major Cobalt Strike TakedownInfosecurity Magazine·Jul 4, 09:30 UTC · Jul 4, 2024Ransomware57
Microsoft Takes Legal Action to Disrupt Cybercriminals' Illegal Use of Cobalt Strike ToolThe Hacker News·Apr 8, 04:44 UTC · Apr 8, 2023Ransomware57
Threat actor ports Cobalt Strike beacon to Linux, uses it in attacksThe Record·Dec 13, 00:00 UTC · Dec 13, 2022Threat actor57
Experts found a link between a Magecart group and Cobalt GroupSecurity Affairs·Oct 8, 14:14 UTC · Oct 8, 2019VulnerabilityCVE-2017-019947
Bug in Cobalt Strike pentesting tool used to identify malicious serversHelp Net Security·Mar 1, 00:00 UTC · Mar 1, 2019Malware42
Additional Entities Targeted by DarkSide Affiliate, TAG-21; Links to WellMess and Sliver InfrastructureRecorded Future·Jul 15, 00:00 UTC · Jul 15, 2025Ransomware57
Global Police Operation Shuts Down 600 Cybercrime Servers Linked to Cobalt StrikeThe Hacker News·Jul 7, 16:50 UTC · Jul 7, 2024Ransomware57
StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike BeaconKaspersky Securelist·Jun 24, 14:23 UTC · Jun 24, 2026MalwareCVE-2021-26855CVE-2023-32315CVE-2024-36401+10 CVEs47
Cobalt Strike: International law enforcement operation tackles illegal uses of ‘Swiss army knife’ pentesting toolThe Record·Jul 3, 15:25 UTC · Jul 3, 2024Ransomware57
Iran-linked COBALT MIRAGE group uses ransomware in its operationsSecurity Affairs·May 13, 06:52 UTC · May 13, 2022RansomwareCVE-2018-13379CVE-2020-12812CVE-2019-5591+3 CVEs60
The Cobalt group is exploiting the CVE-2017-11882 Microsoft Office flaw in targeted attacksSecurity Affairs·Nov 26, 14:06 UTC · Nov 26, 2017VulnerabilityCVE-2017-11882CVE-2017-875947
Uncovering Qilin attack methods exposed through multiple casesCisco Talos·Oct 27, 02:00 UTC · Oct 27, 2025Ransomware57
Emotet directly drops Cobalt Strike beacons without intermediate TrojansSecurity Affairs·Dec 8, 06:32 UTC · Dec 8, 2021Malware42
APT41-Linked Silver Dragon Targets Governments Using Cobalt Strike and Google Drive C2The Hacker News·Mar 4, 14:52 UTC · Mar 4, 2026Threat actor57
APT41 Hackers Use ShadowPad, Cobalt Strike in Taiwanese Institute Cyber AttackThe Hacker News·Aug 2, 16:32 UTC · Aug 2, 2024Threat actorCVE-2018-082460
Hackers Using Golang Variant of Cobalt Strike to Target Apple macOS SystemsThe Hacker News·May 15, 00:00 UTC · May 15, 2023Malware142
Chinese and Russian Hackers Using SILKLOADER Malware to Evade DetectionThe Hacker News·Mar 18, 05:02 UTC · Mar 18, 2023Malware42
Quarterly Report: Incident Response Trends in Q3 2022Cisco Talos·Oct 25, 12:00 UTC · Oct 25, 2022RansomwareCVE-2020-147260
New Malware Campaign Targeting Job Seekers with Cobalt Strike BeaconsThe Hacker News·Oct 1, 05:49 UTC · Oct 1, 2022MalwareCVE-2017-019947
Government, Union-Themed Lures Used to Deliver Cobalt Strike PayloadsInfosecurity Magazine·Sep 29, 17:00 UTC · Sep 29, 2022Vulnerability42
Manjusaka, a new attack tool similar to Sliver and Cobalt StrikeSecurity Affairs·Aug 3, 17:15 UTC · Aug 3, 2022Malware42
LockBit 3.0 sideloads Cobalt Strike through Windows DefenderSecurity Affairs·Aug 2, 12:30 UTC · Aug 2, 2022Ransomware57
Hackers Backdoor Unpatched Microsoft SQL Database Servers with Cobalt StrikeThe Hacker News·Feb 22, 07:22 UTC · Feb 22, 2022Vulnerability42
Loncom packer: from backdoors to Cobalt StrikeKaspersky Securelist·Apr 2, 10:00 UTC · Apr 2, 2020Malware42