Security researchers were targeted by a malicious actor, who sent them PoC for fake Windows exploits , infecting their devices with the Cobalt Strike backdoor.
See also: Windows 11: New desktop search only works with Edge

The hacker behind these attacksappears to have exploited recently patched Windows remote code execution vulnerabilities, known as CVE-2022-24500 and CVE-2022-26809.
When Microsoft patches a vulnerability, it is common for security researchers to analyze the fix and publish PoCs for the flaw on GitHub.
These proof-of-concept exploits are used by security researchers to test their own defenses and push administrators to implement security updates.
However, many times malicious actors also use these exploits to carry out attacks or spread laterally within a network.
Last week, a malicious actor published two proof-of-concept exploits for Windows vulnerabilities CVE-2022-24500 and CVE-2022-26809 on GitHub.
These exploits were published in repositories for a user named 'rkxxz', which have since been removed along with the account.
See also: Ukraine: Fake security updates install Cobalt Strike

As always happens when a PoC is published, the news spread quickly on Twitter and caught the attention of malicious users, who posted the news on hacking.
However, it soon became apparent that these proof-of-concept exploits were fake and installed the Cobalt Strike backdoor on people's devices
Cobalt Strike is a legitimate penetration tool commonly used by threat actors to breach and spread laterally through an organization.
In a later report by cybersecurity firm Cyble, threat analysts analyzed the PoC and found that it was a .NET pretending to exploit an IP address that infected users with Cobalt Strike.
By targeting security researchers, threat actors not only gain access to the research the victim is doing, but they may also gain access to a cybersecurity company's network.
See also: Hackers install Cobalt Strike beacons on Microsoft SQL Servers
As cybersecurity companies tend to have sensitive information about their clients, such as vulnerability assessments, remote access credentials, or even unpatched zero-day vulnerabilities, this type of access can be very valuable to a threat actor.
