logo

Europol nukes nearly 600 IP addresses in Cobalt Strike crackdown

ID: 15ea1bac-395f-5d2c-98d9-b7c9013148d4

STIX ID: report--15ea1bac-395f-5d2c-98d9-b7c9013148d4

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-07-04

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Europol coordinated Operation Morpheus, a week-long international disruption that flagged and disabled hundreds of IP addresses hosting cracked copies of Cobalt Strike, a legitimate red‑teaming tool extensively abused by cybercriminals (including groups linked to ransomware) and nation-state actors; private partners shared more than 730 threat intelligence items and nearly 1.2 million IOCs, while telemetry shows a large share of Cobalt Strike infrastructure is hosted in China and the U.S., underscoring continued risk despite the takedowns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.