logo

Hackers No Hashing: Randomizing API Hashes to Evade Cobalt Strike Shellcode Detection | Huntress

ID: 35993527-ca26-59c6-9df0-518e423cfcae

STIX ID: report--35993527-ca26-59c6-9df0-518e423cfcae

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2024-06-24

Date Updated: 2026-04-28

...
...

This research post analyzes API-hashing techniques used by Metasploit and Cobalt Strike, shows that many vendors rely on default ROR13 hashes for detection, and demonstrates how altering the rotation value (e.g., to ROR15) and small shellcode tweaks can bypass most detections; the authors provide an automated script to generate modified shellcode and a YARA rule that targets the hashing routine itself to improve detection resilience.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.