logo

Recap of a Suspicious Surge in Cobalt Strike

ID: d39c82ca-e9d0-559d-b83f-c95b9b1187e2

STIX ID: report--d39c82ca-e9d0-559d-b83f-c95b9b1187e2

Feed Name: Censys Blog

Threat Score
55/100

Date Published: 2025-12-23

Date Updated: 2026-04-27

Author: Mark Ellzey; Senior Security Researcher

...
...

Censys observed a rapid, short-lived burst of Cobalt Strike listeners in early–mid December 2025 concentrated in two ASes (AS138415 and AS133199), with hundreds of ephemeral hosts spanning newly acquired address blocks (notably 23.235.160.0/19 assigned to RedLuff, LLC). The report documents timeline counts, lists affected IP blocks and six unique Cobalt Strike public keys, and highlights suspicious RIR transfer activity and inconsistent registration/website data for RedLuff that may indicate abuse of freshly transferred IP space for malicious infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.