Cobalt Strike Team Servers: The Great Ransomware Enabler
ID: 6be12267-ca6f-54dd-b825-8cbe865cb40d
STIX ID: report--6be12267-ca6f-54dd-b825-8cbe865cb40d
Feed Name: ReliaQuest Blog
Threat Score
ReliaQuest analyzes heavy weaponization of the legitimate pen‑testing tool Cobalt Strike in Q1 2023, documenting thousands of active team servers (by country and ASN), common C2 ports and registrars, typical spawn-to processes, and the use of CDNs/domain fronting to hide C2; the report emphasizes this infrastructure’s central role in double‑extortion ransomware and provides indicators and defensive guidance for detection and blocking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
