Sophisticated Attacks Employ Cobalt Strike, DLL Sideloading, and Evolving Tactics
ID: 6f459f16-613b-57a4-b9cd-fa64c134e9b8
STIX ID: report--6f459f16-613b-57a4-b9cd-fa64c134e9b8
Feed Name: securityonline.info
Threat Score
*Sophos researchers exposed a late‑2023 to early‑2024 targeted campaign that delivered Cobalt Strike via DLL sideloading, abused expired/compromised certificates, used Minhook for API hooking, and hid payloads in resources and memory; initial detections were in China and Taiwan with subsequent telemetry pointing to Sweden, and the report lists C2 domains and deceptive URIs while urging monitoring of unexpected DLL loads and hooked APIs.*
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
