Operation FrostBeacon is a threat campaign tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed December 9, 2025; most recent activity December 9, 2025.
Operation FrostBeacon is a threat campaign that targets finance and legal departments, using Cobalt Strike malware as the core tool for intrusion and post-exploitation. The campaign underscores the ongoing reliance on Cobalt Strike by threat actors and its effectiveness in pursuing lateral movement and data access within sensitive sectors. This makes FrostBeacon significant for cybersecurity due to its sector focus and use of widely adopted offensive tooling.
Operation FrostBeacon is a cybercrime campaign identified by Seqrite Labs, focusing on finance and legal departments. The campaign employs Cobalt Strike malware to compromise organizations, indicating a sophisticated…