logo

Malicious use of Cobalt Strike down 80% after crackdown, Fortra says

ID: 57b1d3bb-abbb-5674-b2f9-2ecc6cd18451

STIX ID: report--57b1d3bb-abbb-5674-b2f9-2ecc6cd18451

Feed Name: The Record from Recorded Future News

Threat Score
55/100

Date Published: 2025-03-07

Date Updated: 2026-05-01

...
...

Fortra, Microsoft, Health-ISAC and international law enforcement concluded a multi-year operation (Morpheus) that seized and sinkholed hundreds of IP addresses and domains associated with unauthorized copies of Cobalt Strike, resulting in an estimated 80% drop in illicit copies and reduced dwell time for takedowns; the action disrupted infrastructure commonly abused by ransomware gangs and nation-state threat actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.