logo

Sophisticated Attacks Employ Cobalt Strike, DLL Sideloading, and Evolving Tactics

ID: 6f459f16-613b-57a4-b9cd-fa64c134e9b8

STIX ID: report--6f459f16-613b-57a4-b9cd-fa64c134e9b8

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2025-05-01

Date Updated: 2026-04-22

Author: Ddos

...
...

*Sophos researchers exposed a late‑2023 to early‑2024 targeted campaign that delivered Cobalt Strike via DLL sideloading, abused expired/compromised certificates, used Minhook for API hooking, and hid payloads in resources and memory; initial detections were in China and Taiwan with subsequent telemetry pointing to Sweden, and the report lists C2 domains and deceptive URIs while urging monitoring of unexpected DLL loads and hooked APIs.*

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.