HomeSecurityCobalt Strike: Fake Windows exploits target security researchers

Cobalt Strike: Fake Windows exploits target security researchers

Security researchers were targeted by a malicious actor, who sent them PoC for fake Windows exploits , infecting their devices with the Cobalt Strike backdoor.

See also: Windows 11: New desktop search only works with Edge

Cobalt Strike

The hacker behind these attacksappears to have exploited recently patched Windows remote code execution vulnerabilities, known as CVE-2022-24500 and CVE-2022-26809.

When Microsoft patches a vulnerability, it is common for security researchers to analyze the fix and publish PoCs for the flaw on GitHub.

These proof-of-concept exploits are used by security researchers to test their own defenses and push administrators to implement security updates.

However, many times malicious actors also use these exploits to carry out attacks or spread laterally within a network.

Last week, a malicious actor published two proof-of-concept exploits for Windows vulnerabilities CVE-2022-24500 and CVE-2022-26809 on GitHub.

These exploits were published in repositories for a user named 'rkxxz', which have since been removed along with the account.

See also: Ukraine: Fake security updates install Cobalt Strike

security researchers

As always happens when a PoC is published, the news spread quickly on Twitter and caught the attention of malicious users, who posted the news on hacking.

However, it soon became apparent that these proof-of-concept exploits were fake and installed the Cobalt Strike backdoor on people's devices

Cobalt Strike is a legitimate penetration tool commonly used by threat actors to breach and spread laterally through an organization.

In a later report by cybersecurity firm Cyble, threat analysts analyzed the PoC and found that it was a .NET pretending to exploit an IP address that infected users with Cobalt Strike.

By targeting security researchers, threat actors not only gain access to the research the victim is doing, but they may also gain access to a cybersecurity company's network.

See also: Hackers install Cobalt Strike beacons on Microsoft SQL Servers

As cybersecurity companies tend to have sensitive information about their clients, such as vulnerability assessments, remote access credentials, or even unpatched zero-day vulnerabilities, this type of access can be very valuable to a threat actor.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS