logo

CrossC2 Expanding Cobalt Strike Beacon to Cross-Platform Attacks

ID: bc009d1c-9b33-5851-9aad-7be1b3c6d240

STIX ID: report--bc009d1c-9b33-5851-9aad-7be1b3c6d240

Feed Name: JPCERT Blog

Threat Score
78/100

Date Published: 2025-08-14

Date Updated: 2026-04-19

Author: 増渕 維摩(Yuma Masubuchi)

...
...

JPCERT/CC reports a multi-country intrusion campaign (Sep–Dec 2024) that leveraged CrossC2 to create cross-platform Cobalt Strike Beacons and used a custom Nim-based loader (ReadNimeLoader) to sideload and execute Cobalt Strike payloads (via OdinLdr) on Windows and Linux/macOS targets; the attackers also used SystemBC, PsExec, Plink and AD-focused tooling, leaving numerous IOCs (hashes, IPs, domains) and a CrossC2 configuration parser to aid defenders, with attribution linking the activity potentially to BlackBasta.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.