HomeSecurityHackers created Linux Cobalt Strike beacon used in attacks

Hackers create Linux Cobalt Strike beacon used in attacks

An unofficial version of Cobalt Strike Beacon Linux created by unknown threat actors has been detected by security researchers and is being actively used in attacks targeting organizations around the world.

Linux Cobalt Strike beacon

See also: Hackers target their victims' internet connections

Cobalt Strike is a legitimate penetration testing tool designed as an attack framework for red teams (groups of security professionals who act as attackers on their organization's infrastructure to discover security gaps and vulnerabilities.)

Cobalt Strike is also used by threat actors for post-exploitation work after deploying so-called beacons, which provide persistent remote access to compromised devices. Using beacons, attackers can later access compromised servers to collect data or deploy further malware payloads.

Over time, “cracked” copies of Cobalt Strike have been downloaded and shared by threat actors, making it one of the most common tools used in cyberattacks leading to data theft and ransomware. However, Cobalt Strike has always had one weakness – it only supports Windows devices and does not include Linux beacons.

In a new report from security firm Intezer, researchers explain how threat actors have taken to crafting their Linux beacons compatible with Cobalt Strike. Using these beacons, threat actors can now gain persistence and remote command execution on both Windows and Linux machines.

See also: The hacker who caused strokes says he stole 600 million crypto "for fun"!

Completely undetected on VirusTotal

Intezer researchers, who first discovered the beacon re-implementation in August and named it Vermilion Strike, said that the Cobalt Strike ELF binary [VirusTotal] they discovered is not fully detected by anti-malware solutions.

Vermilion Strike comes in the same configuration format as the official Windows beacon and can "talk" to all Cobalt Strike servers, but does not use any of the Cobalt Strike code.

This new Linux malware also has technical overlaps with Windows DLL files that hint at the same developer.

See also: The largest cryptocurrency theft by hackers! 600 million lost.

Applied in continuous attacks since August

Intezer has found multiple organizations that have been targeted with Vermilion Strike since August 2021 – across a variety of industries, from telecommunications companies and government agencies to IT companies, financial institutions, and consulting firms around the world.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS