Cobalt Strike — Malware Profile
Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system. In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.
MITRE ATT&CK techniques (73)
- T1001.003 Protocol or Service Impersonation
- T1003.001 LSASS Memory
- T1003.002 Security Account Manager
- T1005 Data from Local System
- T1007 System Service Discovery
- T1012 Query Registry
- T1016 System Network Configuration Discovery
- T1018 Remote System Discovery
- T1021.001 Remote Desktop Protocol
- T1021.002 SMB/Windows Admin Shares
- T1021.003 Distributed Component Object Model
- T1021.004 SSH
- T1021.006 Windows Remote Management
- T1027 Obfuscated Files or Information
- T1027.005 Indicator Removal from Tools
- T1029 Scheduled Transfer
- T1030 Data Transfer Size Limits
- T1046 Network Service Discovery
- T1047 Windows Management Instrumentation
- T1049 System Network Connections Discovery
- T1055 Process Injection
- T1055.001 Dynamic-link Library Injection
- T1055.012 Process Hollowing
- T1056.001 Keylogging
- T1057 Process Discovery
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1059.005 Visual Basic
- T1059.006 Python
- T1059.007 JavaScript
- T1068 Exploitation for Privilege Escalation
- T1069.001 Local Groups
- T1069.002 Domain Groups
- T1070.006 Timestomp
- T1071.001 Web Protocols
- T1071.002 File Transfer Protocols
- T1071.004 DNS
- T1078.002 Domain Accounts
- T1078.003 Local Accounts
- T1083 File and Directory Discovery
- T1087.002 Domain Account
- T1090.001 Internal Proxy
- T1090.004 Domain Fronting
- T1095 Non-Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1106 Native API
- T1112 Modify Registry
- T1113 Screen Capture
- T1132.001 Standard Encoding
- T1134.001 Token Impersonation/Theft
- T1134.003 Make and Impersonate Token
- T1134.004 Parent PID Spoofing
- T1135 Network Share Discovery
- T1137.001 Office Template Macros
- T1140 Deobfuscate/Decode Files or Information
- T1185 Browser Session Hijacking
- T1197 BITS Jobs
- T1203 Exploitation for Client Execution
- T1218.011 Rundll32
- T1497.002 User Activity Based Checks
- T1518 Software Discovery
- T1543.003 Windows Service
- T1548.002 Bypass User Account Control
- T1548.003 Sudo and Sudo Caching
- T1550.002 Pass the Hash
- T1553.002 Code Signing
- T1564.010 Process Argument Spoofing
- T1569.002 Service Execution
- T1572 Protocol Tunneling
- T1573.001 Symmetric Cryptography
- T1573.002 Asymmetric Cryptography
- T1620 Reflective Code Loading
- T1685 Disable or Modify Tools
IntelFusions coverage
- APT41 Expands into Africa: Kaspersky Uncovers Wicked Panda's Sophisticated Campaign Against Government IT Services 2026-02-16
- Threat Hunting Cobalt Strike: How Researchers Fingerprint and Infiltrate Attacker C2 Infrastructure 2026-02-16
- CISA, FBI, and NSA Joint Advisory: Conti Ransomware Surpasses 1,000 Attacks with TrickBot, Cobalt Strike, and Double Extortion 2026-02-16
- LockBit Affiliate Side-Loads Cobalt Strike via VMwareXferlogs.exe: Malicious glib-2.0.dll Bypasses EDR Hooks, ETW, and AMSI 2026-02-16
- Stately Taurus (Mustang Panda) Conducts Two-Year Southeast Asian Government Espionage Operation: Three-DLL ToneShell Variant, ShadowPad, and Continuous File Exfiltration via Dropbox 2026-02-16
- TA505 Pivots from Phishing to CVE-2021-35211 SolarWinds Serv-U Exploitation: Cobalt Strike Delivery and RegIdleBackup COM Handler Hijacking for FlawedGrace RAT Persistence 2026-02-16
- menuPass (APT10) Deploys Cobalt Strike via Encrypted Executables and DKMC Bitmap Shellcode in Dual-Wave Attacks on Japanese Organizations 2026-02-16
- Hades Ransomware: How INDRIK SPIDER Reinvented Its Toolchain to Evade OFAC Sanctions 2026-02-16
- Leviathan: Chinese Espionage Actor Targets Maritime, Naval Defense, and Military Research with Orz, NanHaiShu, and Cobalt Strike 2026-02-16
- New SharkLoader malware hits diplomats and governments with Cobalt Strike 2026-06-24
- Weaxor ransomware turns SQL Server into its launchpad 2026-08-13
Attributed threat actors
- Play Ransomware
- LuminousMoth machine-inferred link
- AvosLocker machine-inferred link
- DarkSide machine-inferred link
- MirrorFace
- Royal machine-inferred link
- APT19
- Sandworm Team
- Fishing Elephant machine-inferred link
- APT29
- Crimson Palace machine-inferred link
- Earth Lusca
- TA505
- DarkHydrus
- Mustang Panda
- BlackSuit machine-inferred link
- BlackByte
- Lorenz machine-inferred link
- Cinnamon Tempest
- APT27
- 3AM machine-inferred link
- Team46 machine-inferred link
- Weaxor machine-inferred link
- FIN6
- Operation Cobalt Whisper machine-inferred link
- Water Galura machine-inferred link
- FIN7
- Qilin machine-inferred link
- Earth Kurma machine-inferred link
- APT32
- FrostyNeighbor machine-inferred link
- Aquatic Panda
- APT41
- Cactus machine-inferred link
- APT10
- Storm-1811
- Hunters International machine-inferred link
- CopyKittens
- ALPHV/BlackCat machine-inferred link
- Teleboyi machine-inferred link