Download Certificate- CMOs | ECIO | Most Admired Brand | Most Trusted Company

Cybercriminals recreate Cobalt Strike in Linux


By MYBRANDBOOK


Cybercriminals recreate Cobalt Strike in Linux

Cobalt Strike is a legitimate penetration testing tool for Windows systems. This new variant, called Vermilion Strike incorporates features of Cobalt Strike such as a command and control (C2) protocol, remote access capabilities, and the ability to execute shell instructions depending on the author. The source code for Cobalt Strike version 4.0 has been reported leaked online, but most of the malicious attackers tracked by the cybersecurity team appear to be relying on hacked or leaked copies of the software.

 

In August, Intezer uncovered the new ELF implementation of Cobalt Strike's beacon, which appears to have originated from Malaysia.

 

When the researchers reported Vermilion Strike, it went undetected on VirusTotal as malicious software.

 

Built on a Red Hat Linux distribution, the malware is capable of launching beacons, listing files, changing and pulling working directories, appending and writing to files, uploading data to its C2, executing commands via the popen function, and analyzing disk partitions.

 

While capable of attacking Linux builds, Windows samples have also been found that use the same C2 server and contain the same functionality.

 

The researchers worked with McAfee Enterprise ATR to examine the software and have come to the conclusion that Vermilion Strike is being used in targeted attacks against telecoms, government, IT, advisory, and financial organizations worldwide.

 

This is not the only unofficial port of Cobalt Strike, however. There is also geacon, an open source project based on the Golang programming language.

 E-Magazine 
 VIDEOS  Placeholder image

Copyright www.mybrandbook.co.in @1999-2024 - All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of Kalinga Digital Media Pvt. Ltd. is prohibited.
Other Initiatives : www.varindia.com | www.spoindia.org