Cobalt Strike Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
93
occurrences
First Seen
October 31, 2025
Last Seen
July 16, 2026

Cobalt Strike is a malware family tracked across 50 threat clusters and 93 intelligence report mentions on ThreatCluster. First observed October 31, 2025; most recent activity July 16, 2026.

Overview

Cobalt Strike is a commercial post-exploitation framework whose Beacon payload provides remote access, process injection, UAC bypasses, and configurable C2. It is frequently repurposed by threat actors for intrusions, with campaigns such as FrostBeacon leveraging Cobalt Strike to target finance and legal departments, underscoring its enduring significance in adversary tooling.

Related Threat Clusters

Recent Intelligence Reports

  • Unc2447 Sombrat And Fivehands Ransomware Sophisticated Financial Threat — cloud.google.com · July 16, 2026
  • AI-Coded Malware | Analyzing Vibe-Coded AD Enumeration — Huntress · July 8, 2026
  • Hackers Use Compromised Websites and transcript.pdf.js Lure to Deliver PureLog Stealer — Gbhackers · July 3, 2026
  • 012 — attack.mitre.org · July 1, 2026
  • Technical Analysis Mltbackdoor — www.zscaler.com · June 25, 2026
  • Stealthy Mistic Backdoor Targets Enterprise Networks via KongTuke Ransomware Access Broker — Rescana · June 25, 2026
  • StrikeShark Campaign Uses New SharkLoader Malware to Deploy Cobalt Strike Beacon — Gbhackers · June 25, 2026
  • StrikeShark Campaign Uses New SharkLoader Malware to Deploy Cobalt Strike Beacon — Gbhackers · June 25, 2026

CVSS v3.1 Breakdown