Operation FrostBeacon Attacking Finance and Legal Departments with Cobalt Strike Malware
ID: d6019a78-8660-5ed4-bdc4-631cf1dc4390
STIX ID: report--d6019a78-8660-5ed4-bdc4-631cf1dc4390
Feed Name: cybersecurityNews.com
Threat Score
Operation FrostBeacon is a sophisticated phishing-driven campaign targeting Russian finance and legal organizations, using archive LNK files and Word exploits (CVE-2017-0199 and CVE-2017-11882) that drop an HTA to reconstruct a multi-layer obfuscated PowerShell payload; the final payload executes XOR-decoded shellcode in memory to deploy a Cobalt Strike Beacon with process-injection techniques and C2 traffic hidden under legitimate-looking web requests.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
