logo

Malware Targets InfoSec: Fake PoC Delivers Cobalt Strike

ID: 4b8f416d-7184-5124-8aee-466da0625936

STIX ID: report--4b8f416d-7184-5124-8aee-466da0625936

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2025-05-20

Date Updated: 2026-07-16

...
...

Cyble researchers discovered GitHub repositories advertised as POCs for CVE-2022-26809 and CVE-2022-24500 that actually host ConfuserEx-protected .NET malware. The samples display fake exploit output, execute hidden PowerShell via cmd.exe to fetch a Cobalt Strike Beacon, and include network and file IOCs; the report provides technical details, MITRE ATT&CK mappings, and recommendations for the infosec community to avoid untrusted POCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.