Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Cobalt Strike Abuse Dropped 80% in Two Years

Fortra has shared an update on the effects of actions taken to reduce the abuse of Cobalt Strike by threat actors.

Cobalt Strike abuse

The abuse of the popular adversary simulation tool Cobalt Strike has decreased significantly over the past two years, according to Fortra, the product’s developer.

Cobalt Strike is a legitimate post-exploitation tool designed for adversary simulation, but threat actors have found ways to create cracked copies (usually older versions of the product) that they can leverage in their operations.

The tool has been abused by both profit-driven cybercriminals and state-sponsored threat groups.    

In April 2023, Fortra announced teaming up with Microsoft and the Health Information Sharing and Analysis Center (Health-ISAC) to take legal and technical action in an effort to prevent the abuse of Cobalt Strike. This included disrupting attacker infrastructure and filing lawsuits against hackers.

In July 2024, Europol announced the takedown of nearly 600 Cobalt Strike servers linked to cybercrime activities. 

Now, nearly two years after it announced teaming up with Microsoft and Health-ISAC, Fortra reports that the number of unauthorized Cobalt Strike copies seen in the wild has dropped by 80%.

The operation has resulted in more than 200 malicious domains being seized and sinkholed to prevent exploitation by malicious hackers.

“Additionally, the average dwell time—the period between initial detection and takedown—has been reduced to less than one week in the United States and less than two weeks worldwide,” Fortra said

Advertisement. Scroll to continue reading.

The company says its efforts continue. This includes providing information to law enforcement agencies, sending takedown notices to hosting providers, and raising awareness of the illegal use of unauthorized Cobalt Strike copies.

“We actively track these activities to the point of origin, identifying root causes to prevent reoccurrence. We concurrently issue notices on a persistent basis until these illegal versions are removed from web properties. Compliant web properties are also passively monitored in case of reappearance,” Fortra said.

“These efforts are gaining momentum and have entered a new phase of heightened efficacy. Automation processes have been put into place to further increase efficiency and simplify the takedown process. Additionally, just as cybercriminals adapt their techniques, Fortra continuously updates Cobalt Strike’s security controls to thwart cracking attempts and protect legitimate users,” it explained.

Related: Google Making Cobalt Strike Pentesting Tool Harder to Abuse

Related: BadBox Botnet Powered by 1 Million Android Devices Disrupted

Related: Rydox Cybercrime Marketplace Disrupted, Administrators Arrested

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this in-depth briefing on how to protect executives and the enterprises they lead from the growing convergence of digital, narrative, and physical attacks.

Register

Learn how integrating BAS and Automated Penetration Testing empowers security teams to quickly identify and validate threats, enabling prompt response and remediation.

Register

People on the Move

Cybersecurity firm Absolute Security announced Harold Rivas as its new CISO.

Simon Forster has been named the new General Manager of DNS security firm Quad9.

Cybersecurity training company Immersive has named Mark Schmitz as its new CEO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.