logo

Attackers Exploiting Public Cobalt Strike Profiles

ID: 33c7fed6-17ad-5939-8b9a-3345f2a230c2

STIX ID: report--33c7fed6-17ad-5939-8b9a-3345f2a230c2

Feed Name: Palo Alto Networks Unit 42

Threat Score
70/100

Date Published: 2024-06-26

Date Updated: 2026-04-28

Author: Durgesh Sangvikar, Yanhui Jia, Chris Navarrete and Matthew Tennis

...
...

Unit 42 analyzed multiple malicious Cobalt Strike Beacon samples discovered via their ATP platform and found the attackers reused and modified a public Malleable C2 profile (ocsp.profile) to craft evasive HTTP C2 traffic; the report provides three sample SHA256 hashes, associated C2 domains and IPs, traffic captures, and discusses detection challenges and mitigations including machine-learning-based defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.