Category: cobalt strike

Providing Solutions

Telerik UI exploitation leads to cryptominer, Cobalt Strike infections

Attacker targets bugs in a popular web application graphical interface development tool

The Active Adversary Playbook 2022

Cyberattacker behaviors, tactics and tools seen on the frontline of incident response during 2021

Conti and Karma actors attack healthcare provider at same time through ProxyShell exploits

An unpatched Microsoft Exchange Server let both ransomware actors in; Karma just stole data, while Conti encrypted.

Zloader Installs Remote Access Backdoors and Delivers Cobalt Strike

Zloader is a banking trojan with historical ties to the Zeus malware.  Recently, Egregor and Ryuk ransomware affiliates used Zloader for the initial point of entry. Zloader featured VNC remote access capabilities and was offered on the infamous Russian-speaking cybercrime forum exploit[.]in. Zloader infects users by leveraging malicious web advertising to redirect users into downloading…
Read more