logo

Cobalt Strike Operators Leverage PowerShell Loaders Across Chinese, Russian, and Global Infrastructure

ID: 54268a13-463b-55af-afb2-efc70fada041

STIX ID: report--54268a13-463b-55af-afb2-efc70fada041

Feed Name: Hunt.io Blog

Threat Score
75/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

A PowerShell shellcode loader (y1.ps1) found in an open directory on a Chinese host executes decrypted shellcode entirely in memory (using reflective techniques and API hashing), contacts a Baidu Cloud Function endpoint to download a second-stage payload, and ultimately deploys a Cobalt Strike Beacon that communicates with IP 46.173.27.142 (Beget LLC, Russia). The report provides technical analysis of the loader and shellcode, associated IOCs (SHA-256 hashes, domains, and multiple IP hosts across regions), SSL certificate metadata referencing "cobaltstrike", hunting queries used to find related scripts, and recommended mitigations such as tightening PowerShell policies, blocking IOCs, and enabling EDR/ASR protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.