HomeSecurityHas the source code of the Cobalt Strike toolkit been released online?

Has the source code of the Cobalt Strike toolkit been released online?

The source code for the widely used Cobalt Strike toolkit has reportedly been leaked online in a GitHub repository.

Cobalt Strike is a penetration testing toolkit that allows attackers to deploy “beacons” on compromised devices to remotely create shells, execute PowerShell scripts, or perform privilege escalation on the attacked system.

Cobalt Strike

Cobalt Strike is an extremely popular tool among hackers who use cracked versions to gain remote access to a compromised network. This tool is commonly used during ransomware.

Twelve days ago, a repository was created on GitHub containing the source code for Cobalt Strike 4.0.

Cobalt Strike

Based on the file “src/main/resources/about.html”, this source code is for Cobalt Strike 4.0 which was released on December 5, 2019.

Cobalt Strike

As can be seen from the source code that you can see below, the Cobalt Strike license check has been “changed”, which apparently “breaks” the program

Cobalt Strike

Vitali Kremez, who reviewed the source code, told BleepingComputer that he believes the Java was “decomposed” manually. The person then fixed any dependencies and removed the license check so that it could be rebuilt.

Since its publication, the source code repository has been modified 172 times.

Although it is not the original source code, it is enough to cause concern among security.

“The fact that the source code of the “2019” version of Cobalt Strike 4.0 was probably released “reconstructed” has significant consequences, as it removes the barriers to entry in obtaining the tool and essentially makes it easier for hacking groups to procure and modify the code, as needed during operations .”

“The leak of the tool opens the door to additional improvement of the tool as is the case with most malware, such as Zeus 2.0.8.9. and TinyNuke which were continuously reused and updated by hackers after the leak,” Kremez told BleepingComputer.

BleepingComputer has contacted Cobalt Strike and their parent company Help Systems to confirm the authenticity of the source code, but has not yet received a response.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS