logo

Cobalt on the weekends

ID: e2ca13d7-864d-5a00-87ae-9e1f00e06157

STIX ID: report--e2ca13d7-864d-5a00-87ae-9e1f00e06157

Feed Name: IntelInsights (Substack)

Threat Score
67/100

Date Published: 2025-06-08

Date Updated: 2026-04-19

Author: Vasilis Orlof

...
...

The report documents a pivot-driven hunt for Cobalt Strike C2 infrastructure starting from a single domain/IP and expanding via certificate fingerprints, HTTP header/banner hashes, JARM, and ASN clustering; it identifies roughly 250 IoCs across providers such as Tencent, DigitalOcean, and HostPapa, notes certificate impersonation of Cloudflare/Microsoft to enhance legitimacy, and shares a link to the full IoC list for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.