Operation FrostBeacon: Multi-Cluster Cobalt Strike Campaign Targets Russia
ID: c82e02eb-33d4-52e7-8c47-0cd48e5e566d
STIX ID: report--c82e02eb-33d4-52e7-8c47-0cd48e5e566d
Feed Name: Seqrite Blog
Operation FrostBeacon is a targeted, financially motivated campaign delivering Cobalt Strike beacons to Russian B2B organizations (finance and legal functions) via two infection clusters: (1) phishing archives containing LNK shortcuts that launch mshta/HTA and obfuscated PowerShell loaders, and (2) malicious DOCX files abusing CVE-2017-0199 (often chained with CVE-2017-11882) to fetch remote HTA payloads. The campaign uses layered encoding and in-memory shellcode execution to deploy Cobalt Strike with custom malleable C2 profiles; the report includes detailed IOCs, domains, URLs, proxy IPs, MITRE TTP mappings and vendor detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
