216.73.216.226

CrossC2 Expanding Cobalt Strike Beacon to Cross-Platform Attacks

· Published 15/08/2025 11:38 · Modified 15/08/2025 13:07

Export JSON

Essential information

Published
15/08/2025 11:38
Modified
15/08/2025 13:07
Tags
2025-08-15 ad cobalt strike crossc2 linux macos odinldr psexec readnimeloader systembc
Related entities
1 intrusion sets (apt), 9 techniques (mitre), 4 malware, 1 others

Description

From September to December 2024, incidents involving , an extension tool for Beacon on , were confirmed. The attacker used along with other tools like , Plink, and to penetrate . A custom malware called was used as a loader for . The campaign may have affected multiple countries. is an unofficial Beacon and builder compatible with 4.1+, designed for and . It contains anti-analysis features and encrypted configuration data. The attack flow involved java.exe, , and to execute Beacon. Other tools used include , GetNPUsers, and privilege escalation tools. The campaign shows potential connections to BlackBasta based on similar characteristics.

External references