HomeSecurityEuropol: Removal of 593 Cobalt Strike servers used by hackers

Europol: Removal of 593 Cobalt Strike servers used by hackers

Europol coordinated an operation called “ Operation Morpheus ,” which led to the removal of nearly 600 Cobalt Strike servers , which were being used by hackers to infiltrate networks.

Europol: Removal of 593 Cobalt Strike servers used by hackers

In late June, law enforcement authorities identified known IP addresses associated with criminal activity and domain names that were part of the criminal groups' attack infrastructure

After detection, Internet service providers received the collected information and were asked to disable unlicensed versions of the tool.

Older, unlicensed versions of the Cobalt Strike tool were targeted during a week-long operation coordinated by Europol headquarters (between 24 and 28 June),” Europol said.

See also: Europol: Removes servers related to malware

A total of 690 IP addresses were flagged to ISPs in 27 countries. By the end of the week, 593 of these addresses had been removed.“.

Operation Morpheus was coordinated by Europol but was a joint effort by law enforcement authorities from Australia, Canada, Germany, the Netherlands, Poland, and the United States and the United Kingdom.

Also, companies such as BAE Systems Digital Intelligence, Trellix, Spamhaus, abuse.ch and The Shadowserver Foundation participated in the operation and helped identify the Cobalt Strike servers used by the hackers, through their improved scanning, telemetry and analysis tools.

The removal of the 593 servers is the result of a complex investigation that began a long time ago, specifically in 2021.

During this long-term investigation, authorities found a lot of evidence about the threats associated with these servers. In addition, Europol organized more than 40 coordination meetings between law enforcement agencies and private partners.

During June 24-28, the week of the removal of the Cobalt Strike servers, Europol created a virtual command center to coordinate the actions of authorities around the world.

It's worth noting that Cobalt Strike was released by Fortra a decade ago as a legitimate penetration testing tool for scanning network infrastructure for vulnerabilities. However, hackers are exploiting it and using it in attacks to steal data and deploy ransomware.

See also: Dozens of arrests of people committing Vishing scams

Attackers use Cobalt Strike during the post-exploitation stage of the attack to deploy beacons that provide persistent remote access to compromised networks.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Europol Cobalt Strike hackers

Meaning of Operation Morpheus

Europol's removal of 593 Cobalt Strike servers is an important step in strengthening cybersecurity. These servers were used by cybercriminals to infiltrate networks and perform malicious actions, such as data theft and ransomware installation.

By neutralizing these servers, the ability of cybercriminals to attack organizations and individuals is significantly reduced. This means that attacks will become more difficult and less effective.

Europol's action also sends a strong message to cybercriminals that authorities are capable of identifying and neutralizing their infrastructure. This may act as a deterrent to future attacks and force criminals to reconsider their strategies.

See also: USA: Two arrested for laundering proceeds from pig butchering scams

Furthermore, Europol’s removal of the Cobalt Strike servers may encourage other international authorities and organizations to step up their efforts to combat cybercrime. International cooperation and coordination are crucial to addressing this global threat, as we have seen in this case.

Finally, this action can lead to increased awareness and education of organizations about cybersecurity. Organizations should review their security measures and adopt best practices to protect their systems and data from future attacks.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS