Striking Back at Retired Cobalt Strike: A look at a legacy vulnerability
ID: c91fa948-5715-5935-b3db-cf56a15f75ee
STIX ID: report--c91fa948-5715-5935-b3db-cf56a15f75ee
Feed Name: NCC Research
Threat Score
This report analyzes the internals of Cobalt Strike 3.5 beacon communications and documents a historical directory-traversal vulnerability in the beacon metadata IP field that enabled unauthenticated remote code execution on the Team Server; it includes staging and encryption details, proof-of-concept exploitation steps (writing files/cronjobs via DOWNLOAD_START/DOWNLOAD_WRITE callbacks), and the mitigation changes introduced in Cobalt Strike 3.5.1.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
