Attackers Exploiting Public Cobalt Strike Profiles
ID: 33c7fed6-17ad-5939-8b9a-3345f2a230c2
STIX ID: report--33c7fed6-17ad-5939-8b9a-3345f2a230c2
Feed Name: Palo Alto Networks Unit 42
Date Published: 2024-06-26
Date Updated: 2026-04-28
Author: Durgesh Sangvikar, Yanhui Jia, Chris Navarrete and Matthew Tennis
Unit 42 analyzed multiple malicious Cobalt Strike Beacon samples discovered via their ATP platform and found the attackers reused and modified a public Malleable C2 profile (ocsp.profile) to craft evasive HTTP C2 traffic; the report provides three sample SHA256 hashes, associated C2 domains and IPs, traffic captures, and discusses detection challenges and mitigations including machine-learning-based defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
