HomeSecurityNew Cobalt Strike denial of service (DoS) vulnerabilities identified

New Cobalt Strike denial of service (DoS) vulnerabilities identified

Security researchers have discovered Cobalt Strike denial of service (DoS) vulnerabilities that allow the blocking of beacon command-and-control (C2) communication channels and new deployments.

Cobalt Strike is a legitimate penetration testing tool designed to be used as an attack framework by red teams (groups of security professionals who act as attackers on their organization's infrastructure to discover security gaps and vulnerabilities.)

See also: Hackers combine ransomware and DDoS attacks to target victims

Cobalt Strike

However, Cobalt Strike is also used by threat actors (typically used during ransomware attacks) for post-exploit operations after deploying so-called beacons, which give them persistent remote access to compromised devices.

Using these beacons, attackers can later gain access to compromised servers to collect data or deploy second-stage malware payloads.

See also: Google: Uses machine learning to prevent DDoS attacks

Targets in the attackers' infrastructure

SentinelLabs (the threat research team at SentinelOne) found that DoS vulnerabilities collectively collected as CVE-2021-36798 (and named Hotcobalt) in the latest versions of the Cobalt Strike server .

As they discovered, someone can register fake beacons on the server of a specific Cobalt Strike installation. By sending fake tasks to the server, one can “crash” the server by exhausting the available memory.

The crash can render already deployed beacons unable to communicate with the C2 server, prevent the installation of new beacons on compromised systems, and affect the current operations of the red team (or malicious actors) that used the deployed beacons.

Since Cobalt Strike is also heavily used by threat actors for various nefarious purposes, law enforcement and security researchers can also use Hotcobalt vulnerabilities to “take down” malicious infrastructure.

See also: 2021: 2.9 million DDoS attacks in the first three months

On April 20, SentinelLabs disclosed the vulnerabilities to CobaltStrike's parent company HelpSystems, which addressed them in Cobalt Strike 4.4, released earlier today.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS