logo

Uncorking Old Wine: Zero-Day from 2017 + Cobalt Strike Loader in Unholy Alliance

ID: 8bf3d4d6-ddaf-57e0-b5c7-398ad18b8869

STIX ID: report--8bf3d4d6-ddaf-57e0-b5c7-398ad18b8869

Feed Name: Deep Instinct Blog

Threat Score
75/100

Date Published: 2024-04-25

Date Updated: 2026-04-27

Author: Ivan Kosarev

...
...

- Deep Instinct Threat Lab identified a suspected targeted operation against Ukraine delivering a malicious PPSX exploiting CVE-2017-8570 which fetches an obfuscated JSE that drops a payload disguised as Cisco AnyConnect (vpn.sessings); the file is a custom DLL loader that unpacks and self-injects a cracked Cobalt Strike Beacon, implements anti-analysis techniques (CPUID VM checks, NtDelayExecution, attempted ntdll unhooking), achieves persistence via registry keys, and communicates with C2 domains weavesilk.space and petapixel.fun; IOCs and MITRE ATT&CK mappings are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.