Cobalt Strike Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
95
occurrences
First Seen
October 31, 2025
Last Seen
July 23, 2026

Cobalt Strike is a malware family tracked across 50 threat clusters and 95 intelligence report mentions on ThreatCluster. First observed October 31, 2025; most recent activity July 23, 2026.

Overview

Cobalt Strike is a commercial post-exploitation framework whose Beacon payload provides remote access, process injection, UAC bypasses, and configurable C2. It is frequently repurposed by threat actors for intrusions, with campaigns such as FrostBeacon leveraging Cobalt Strike to target finance and legal departments, underscoring its enduring significance in adversary tooling.

Related Threat Clusters

Recent Intelligence Reports

  • T1620 — attack.mitre.org · July 23, 2026
  • 001 — attack.mitre.org · July 23, 2026
  • Unc2447 Sombrat And Fivehands Ransomware Sophisticated Financial Threat — cloud.google.com · July 16, 2026
  • AI-Coded Malware | Analyzing Vibe-Coded AD Enumeration — Huntress · July 8, 2026
  • Hackers Use Compromised Websites and transcript.pdf.js Lure to Deliver PureLog Stealer — Gbhackers · July 3, 2026
  • 012 — attack.mitre.org · July 1, 2026
  • Technical Analysis Mltbackdoor — www.zscaler.com · June 25, 2026
  • Stealthy Mistic Backdoor Targets Enterprise Networks via KongTuke Ransomware Access Broker — Rescana · June 25, 2026

CVSS v3.1 Breakdown