logo

Hackers now use AppDomain Injection to drop CobaltStrike beacons

ID: b782de24-edd6-574c-813e-697e53570843

STIX ID: report--b782de24-edd6-574c-813e-697e53570843

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-08-23

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

NTT Japan observed a July 2024 campaign using AppDomainManager Injection and the GrimResource MSC exploit to create malicious exe.config and DLL files adjacent to signed Microsoft executables, enabling stealthy execution of Cobalt Strike beacons; victims include government, military, and energy organizations in Taiwan, the Philippines, and Vietnam, and overlaps with other reporting suggest (low-confidence) APT41 involvement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.