HomeSecurityHow hackers use the penetration testing tool Cobalt Strike

How hackers use the penetration testing tool Cobalt Strike

New research shows how Cobalt Strike is being used in campaigns that spread malware, from the Trickbot banking Trojan to Bazar.

Cobalt Strike

See also: Conti ransomware also targeted the Irish Ministry of Health!

On Wednesday, Intel 471 published a report investigating the misuse of Cobalt Strike, a penetration testing tool released in 2012 that can be used to deploy beacons in attack simulation systems and network defense tests.

In January, security analysts reported that Cobalt Strike, alongside the Metasploit framework, was used to host over 25% of all malicious command-and-control (C2) servers deployed in 2020.

See also: CISA published detailed analysis of FiveHands ransomware!

The popular penetration testing kit, whose source code for version 4.0 was reportedly leaked online in 2020, has been used by various threat actors for years and has become a tool of various advanced persistent threat (APT) groups, including Carbanak and Cozy Bear.

According to Fox-IT, thousands of cases of Cobalt Strike abuse have been recorded, but most threat actors use cracked or old versions of the software.

Researchers say that existing abuse of Cobalt Strike has been linked to campaigns ranging from ransomware to data exfiltration, but because the tool allows users to create malleable C2 architectures, it can be complicated to track down C2 holders.

However, the team conducted research into the use of Cobalt Strike in post-exploitation activities.

Trickbot was chosen as a starting point. The operators of the Trickbot banking Trojan have used Cobalt Strike in attacks dating back to 2019 – alongside Meterpreter and PowerShell Empire – as well as in attacks detected by Walmart Global Tech and SentinelLabs.

The Hancitor group (MAN1/Moskalvzapoe/TA511), has also begun using Cobalt Strike. It was also linked to the development of the Gozi Trojan and Evil Pony, and as noted by Palo Alto Networks, recent infections have shown that these tools have been replaced by Cobalt Strike. During post-exploit activities, the Hancitor group deploys either a Remote Access Trojan (RAT), information stealers, or, in some cases, spambot malware.

Learn: Cuba ransomware collaborates with Hancitor malware for spam attacks

Researchers are also investigating the use of Cobalt Strike by threat actors distributing the Qbot/Qakbot banking Trojan, one of whose plugins – plugin_cobalt_power3 – enables the penetration testing tool.

Operators of various variants of the SystemBC malware, as reported by Proofpoint, use SOCKS5 proxies to cloak network traffic and have been included as payloads in the RIG and Fallout exploit kits. According to Intel 471, ransomware operators have also adopted SystemBC, which was used by Cobalt Strike during its campaigns launched in 2020 and early 2021. However, these recent campaigns have not been attributed to specific, known threat actors.

Also, in early 2021, Bazar campaigns were recorded as shipping and distributing campaigns for Cobalt Strike rather than the typical Bazar loaders used by threat actors in the past.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS