Targeted attacks leverage accounts on popular online platforms as C2 servers
Essential information
- Published
- 30/07/2025 14:41
- Modified
- 30/07/2025 14:52
- Tags
- 2025-07-30 api obfuscation c2 communication cobalt strike cobalt strike beacon dll hijacking shellcode social media spear-phishing targeted attacks
- Related entities
- 2 observables, 1 techniques (mitre), 1 malware, 7 others
Description
A sophisticated cyberattack campaign targeted the Russian IT industry and other entities globally in late 2024. The attackers used social media profiles and popular websites to deliver payload information, bypassing detection methods. They employed spear phishing emails with malicious RAR archives, exploiting DLL hijacking techniques to deploy Cobalt Strike Beacon. The campaign used profiles on GitHub, Microsoft Learn Challenge, Quora, and Russian social networks to conceal activities. The attacks primarily focused on Russian companies but also affected organizations in China, Japan, Malaysia, and Peru. The complexity of the methods used highlights the evolving tactics of threat actors in concealing well-known tools and emphasizes the need for robust cybersecurity measures.