Operation FrostBeacon — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
December 9, 2025
Last Seen
December 9, 2025

Operation FrostBeacon is a threat campaign tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed December 9, 2025; most recent activity December 9, 2025.

Overview

Operation FrostBeacon is a threat campaign that targets finance and legal departments, using Cobalt Strike malware as the core tool for intrusion and post-exploitation. The campaign underscores the ongoing reliance on Cobalt Strike by threat actors and its effectiveness in pursuing lateral movement and data access within sensitive sectors. This makes FrostBeacon significant for cybersecurity due to its sector focus and use of widely adopted offensive tooling.

Related Threat Clusters

Recent Intelligence Reports

  • Operation FrostBeacon Attacking Finance and Legal Departments with Cobalt Strike Malware — Cybersecuritynews · December 9, 2025
  • Cobalt Strike Malware Strikes Finance and Legal Departments in Operation FrostBeacon — Cyberpress · December 9, 2025

Related Entities

CVSS v3.1 Breakdown