Cobalt Strike Beacon delivered via GitHub and social media
ID: 69d56c41-d75e-5085-80b2-bd55df5bd739
STIX ID: report--69d56c41-d75e-5085-80b2-bd55df5bd739
Feed Name: Securelist by Kaspersky
Date Published: 2025-07-30
Date Updated: 2026-04-29
Author: Maxim Starodubov, Valery Akulenko, Danila Semenov
Kaspersky analysed an active spear‑phishing campaign (Nov 2024–Apr 2025) targeting primarily Russian IT and oil & gas organizations that used RAR archives and LNK shortcuts to drop a malicious BugSplatRc64.dll which hijacks a legitimate crash-reporting utility (BsSndRpt.exe). The malicious DLL uses dynamic API resolution and hooks (e.g., MessageBoxW) to fetch XOR/base64‑encoded payload addresses hidden in public profiles on platforms like GitHub, Quora and Microsoft Learn, downloads an additional XOR-encrypted shellcode that loads a reflective Cobalt Strike Beacon, and the report provides IoCs and detection names.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
