logo

Operation FrostBeacon Attacking Finance and Legal Departments with Cobalt Strike Malware

ID: d6019a78-8660-5ed4-bdc4-631cf1dc4390

STIX ID: report--d6019a78-8660-5ed4-bdc4-631cf1dc4390

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Operation FrostBeacon is a sophisticated phishing-driven campaign targeting Russian finance and legal organizations, using archive LNK files and Word exploits (CVE-2017-0199 and CVE-2017-11882) that drop an HTA to reconstruct a multi-layer obfuscated PowerShell payload; the final payload executes XOR-decoded shellcode in memory to deploy a Cobalt Strike Beacon with process-injection techniques and C2 traffic hidden under legitimate-looking web requests.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.