logo

Operation FrostBeacon: Multi-Cluster Cobalt Strike Campaign Targets Russia

ID: c82e02eb-33d4-52e7-8c47-0cd48e5e566d

STIX ID: report--c82e02eb-33d4-52e7-8c47-0cd48e5e566d

Feed Name: Seqrite Blog

Threat Score
75/100

Date Published: 2025-12-08

Date Updated: 2026-04-30

Author: Rayapati Lakshmi Prasanna Sai

...
...

Operation FrostBeacon is a targeted, financially motivated campaign delivering Cobalt Strike beacons to Russian B2B organizations (finance and legal functions) via two infection clusters: (1) phishing archives containing LNK shortcuts that launch mshta/HTA and obfuscated PowerShell loaders, and (2) malicious DOCX files abusing CVE-2017-0199 (often chained with CVE-2017-11882) to fetch remote HTA payloads. The campaign uses layered encoding and in-memory shellcode execution to deploy Cobalt Strike with custom malleable C2 profiles; the report includes detailed IOCs, domains, URLs, proxy IPs, MITRE TTP mappings and vendor detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.