Multiple Cobalt Strike Beacons Detected on Various Ports

Multiple Cobalt Strike Beacons Detected on Various Ports

First seen 9 Sep 2026, 20:44 UTC Redpacketsecurity 33.9

Article Content

Browse articles
ThreatCluster

On September 9, 2026, multiple instances of Cobalt Strike beacons were detected across various IP addresses and ports. The affected IPs include 196.251.121.183:4433, 14.225.212.124:30005, 154.12.94.16:2087, 137.220.151.95:8888, 27.71.16.98:443, and 119.45.160.160:8889. Cobalt Strike is a well-known penetration testing tool often misused by threat actors for malicious purposes. The articles caution that the detections may be false positives and recommend further validation. The current status of these detections remains uncertain, with no specific details on the scope of impact or targeted organizations. Security professionals are advised to monitor their networks for these indicators of compromise (IOCs).

Key Points: • Multiple Cobalt Strike beacons detected on September 9, 2026. • Affected IPs include 196.251.121.183, 14.225.212.124, and others. • Cobalt Strike is frequently misused by threat actors.

Ask AI about this cluster

Timeline

2026-09-09
Cobalt Strike beacon detected
Multiple IPs were reported as Cobalt Strike beacons, including 196.251.121.183:4433 and 14.225.212.124:30005.
Redpacketsecurity
2026-09-09
Additional beacons reported
Further detections included IPs 154.12.94.16:2087, 137.220.151.95:8888, and others, all flagged as Cobalt Strike.
Redpacketsecurity