logo

Striking Back at Retired Cobalt Strike: A look at a legacy vulnerability

ID: c91fa948-5715-5935-b3db-cf56a15f75ee

STIX ID: report--c91fa948-5715-5935-b3db-cf56a15f75ee

Feed Name: NCC Research

Threat Score
30/100

Date Published: 2025-12-02

Date Updated: 2026-08-01

...
...

This report analyzes the internals of Cobalt Strike 3.5 beacon communications and documents a historical directory-traversal vulnerability in the beacon metadata IP field that enabled unauthenticated remote code execution on the Team Server; it includes staging and encryption details, proof-of-concept exploitation steps (writing files/cronjobs via DOWNLOAD_START/DOWNLOAD_WRITE callbacks), and the mitigation changes introduced in Cobalt Strike 3.5.1.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.