1,289 Cobalt Strike indicators in 48 hours, from a tool that has been cracked, leaked, rented and bought. An indicator tells you the tool, never the operator. The TTPs tell you the rest.
1. The pile of indicators
On 7 October 2026 the biggest family in this site’s Threat orrery was Cobalt Strike. In 48 hours ThreatFox logged 1,289 indicators for it: 666 domains, 622 ip:port pairs and one URL, mostly in China, the US and Hong Kong. The next family down had about half as many. That isn’t one noisy actor. It’s what a commercial red team tool looks like once it has slipped its license, and the pile doesn’t shrink on its own.
Context
An indicator of compromise (IOC) is a piece of evidence that points at an intrusion: an IP and port, a domain, a URL, a file hash. Indicators are cheap to publish and quick to expire, which is why one tool can fill a feed. ThreatFox, the abuse.ch platform behind these numbers, takes submissions from anyone, so a count measures how much was reported, not how many operators there are.

This post is about how it got that way, what a cracked copy hands even a novice, where Matanbuchus and Shellter fit, how to recognise the implant itself, and a part I haven’t seen written up: a seller who supplies EDR test panels and, on my evidence, sets up companies to buy the legitimate tools.

2. Cracked copies are the baseline
Cobalt Strike 4.0 shipped on 5 December 2019. In November 2020 someone posted a hand-decompiled copy of it to GitHub with the license check commented out, so anyone could compile it. It was forked 172 times.
That wasn’t the first crack and it wasn’t the last. Google Cloud Threat Intelligence catalogued 34 release versions and 275 unique JARs of leaked and cracked Cobalt Strike, from 1.44 up to 4.7, and wrote 165 YARA signatures for them. Their useful observation is that the abused copies sit at least one release behind what paying customers run. Fortra says the unauthorized copies it is chasing come from illegal marketplaces.
Cracked builds also tend to patch the per-license watermark in the beacon config to a fixed value. The watermark has been there since 3.10 in December 2017 and was meant to be unique per customer. A patched one is how you tell a pirated beacon from a pen tester’s.
3. What a cracked copy hands you
Context
Cobalt Strike is a commercial adversary-simulation tool that Fortra sells to red teams. It has two halves: a team server the operators connect to, and Beacon, the implant that runs on the target and checks in. A malleable C2 profile sets what Beacon’s traffic looks like. The Artifact Kit, Resource Kit and Sleep Mask Kit let licensed customers change the executables, the script templates and how Beacon behaves in memory while it sleeps.
Cobalt Strike isn’t a payload, it’s a post-exploitation framework. A team server holds the listeners, the malleable C2 profile and the logs. Beacon is a small check-in loop that does what it’s told. Nearly everything else is tasked after access. MITRE’s entry for the tool lists credential dumping, lateral movement over SMB shares, WinRM, DCOM and service execution, process injection, relays between Beacons, port scanning, keylogging, screenshots and browser session hijacking, carried over HTTP, HTTPS, DNS and SMB named pipes.
That’s the difference from what it gets lumped in with. A hobby C++ implant does what its author compiled in. A commodity RAT does what the seller’s builder bakes into the client. With Cobalt Strike the capability is tasked from the team server once a foothold lands, so the ceiling is whoever is at the keyboard.

Context
LSASS (lsass.exe) is the Windows process that checks logons and keeps the credentials of signed-in users in its memory. Mimikatz is a public tool that reads them out. Cobalt Strike carries a wrapper for it, so an operator with administrator or SYSTEM rights on a host they already control can pull hashes and passwords from it.
The capability defenders meet first is credential theft. Beacon wraps Mimikatz, and MITRE records it as a job that injects into LSASS memory to dump password hashes (T1003.001). An operator can also drop to a shell and run Mimikatz by hand. Either way it needs high privilege on the host, which is why it comes after a foothold and not before. In its 2022 threat report Sophos found Mimikatz the tool it came across most often, with Metasploit and Cobalt Strike components turning up often too.
Context
Fork and run is how Beacon runs most of its tools. It starts a throwaway process, injects the tool into it, reads the output back over a named pipe and lets the process die. That keeps a crash out of Beacon itself, and it leaves a pattern a defender can see. Beacon Object Files, added in 4.1, run inside the Beacon process instead.
It’s also the part you can see. In Splunk’s testing the sacrificial process was rundll32.exe with no arguments. Sysmon event ID 10 against lsass.exe with a suspicious access mask is the classic catch, and Splunk’s post lists the masks. Beacon Object Files, added in 4.1, skip the sacrificial process, so a rule built on that pattern alone will miss them.
On the prevention side, LSA protection stops unprotected processes reading LSASS memory, and it’s on by default for new, enterprise-joined, HVCI-capable Windows 11 22H2 installs. Credential Guard goes further. Neither is a guarantee. They take away the easy route.
Now the copies. Google found cracked Cobalt Strike up to 4.7, across 34 versions and 275 JARs, and the 4.7 leak is public: it has been posted on hackforums.net, an open forum, for anyone to take, and Sophos had its code circulating on file-sharing sites since the fall of 2022. The package I looked at carries only the stock Artifact32, the executable loader Beacon gets wrapped in (Fortra’s guide says Cobalt Strike generates these from the Artifact Kit), and the Resource Kit. The Sleep Mask Kit is not in it. Google’s rule set has separate rules for Artifact32, Artifact32svc and Artifact64 across the version range, so the stock loaders are exactly what it signs.
That is what put 4.7 in reach of low-level actors: start the team server, generate a payload, send it. No compiler, no Artifact Kit, no idea how a loader works. Licensed customers get the kits’ source through the Arsenal so they can change those parts when the stock ones get caught. A novice running the leak as posted gets the stock signatures.
4. Exposure, not skill, is what changed
More people can run Cobalt Strike than can use it. Proofpoint’s 2021 report found more cybercrime and commodity malware operators using it than APT and espionage actors, and a 161% rise in attacks that used it between 2019 and 2020. As the trade press reported it, the appeal is that the built-in capabilities can be deployed quickly regardless of an actor’s sophistication.
Here is my read, which is inference and not something those sources say. Most people who pick up a cracked copy can’t do much with it. They get a beacon on a box and stall: no privilege to dump credentials, no feel for how an Active Directory estate hangs together, no plan past the first host. They run it the way it came, with stock artifacts, the default profile and often the default TLS certificate. That last habit is documented. Recorded Future found criminal and state-aligned operators alike running default, unpatched configurations in 2019, and used the default certificate to find the servers.
The same tool in the right hands is another thing. Sophos found it was most often part of the hands-on-keyboard attacks that ransomware groups prefer. A crew with a plan, a rebuilt loader and a profile of its own uses the same beacon to move through a network and finish the job.
That spread is what a feed can’t show. A thousand Cobalt Strike indicators include a novice’s default team server that’s up for a day and a ransomware affiliate’s staging server. They carry the same family label and match the same YARA rule. The count tells you how exposed the tool is. It tells you nothing about how dangerous any one hit is.
5. Everything looks like everything else
Put a cracked XWorm next to a cracked Cobalt Strike and the difference is where the variation lives. A commodity RAT is one code base: a builder, a stub and a panel. Everyone who runs a crack of it runs the same stub, so the same strings, mutexes, config layout and network habits turn up on thousands of machines. That is a fixed target for defenders. The crack is public, so they can build samples whenever they like, pull the configs, and write a heuristic or behavioural rule once that hits every copy.
Context
Heuristic detection scores a file on its traits: the packer, the imports, the strings. Behavioural detection scores what a process does: what it spawns, what it injects into, who it talks to. Both work best on a code base that doesn’t change, because the same stub gives the same traits and the same behaviour every time.
The cracks are also a trap for the people who run them. CloudSEK found a trojanized XWorm builder, passed around GitHub, file hosts, Telegram and YouTube as a free copy, that backdoored 18,459 devices.
A Beacon isn’t bound to that. It’s a small foothold whose behaviour the operator sets. Since Cobalt Strike 2.0 in July 2014 the operator has written the malleable C2 profile that decides what Beacon’s traffic looks like. A licensed operator can also rebuild the loader and change how Beacon sits in memory, and every operator picks their own sleep and jitter, their own spawn-to process and their own listeners. So two Beacons from the same 4.7 crack aren’t bound to the same ruleset. A rule written for one operator’s profile misses the next, and the signatures that catch the stock copy catch only the operators who changed nothing. What stays the same is what the operator does once the foothold is in, which is why sections 3 and 10 look at behaviour and not at the file.
That doesn’t make the network side private. Even with a clean license, much of it is shared. Unit 42 found actors reusing public malleable C2 profiles (an ocsp.profile from GitHub in their case) with trivial edits: a bumped User-Agent, new URIs, a spoofed company name on the C2 domain. Domains, URIs and User-Agents end up common to groups that have nothing to do with each other.
The other half is that defenders find team servers the same way attackers deploy them. A default team server answers a checksum8 request with a beacon, so researchers and scanners pull configs at scale. That’s a lot of IOCs, and almost none of them tell you who is behind them.
And the Beacon is rarely the end of the chain. It’s a foothold that fetches the next stage. On my evidence, the foothold beacons I follow pull their second-stage payloads from TeamSpeak servers. That is my observation, and I haven’t found a public report of it. My reading, which is inference: voice-chat traffic to a game-server port is the kind of traffic nobody inspects, so a payload fetched that way misses both the web filter and the profile-based hunting above.
That is the latest step in a long line, and the history explains why. Every generation of command and control moved the part a defender could pin on it: a port, a channel, a domain, an algorithm, and now a profile the operator writes.

Scope
This chronology is sparse, and it is fixated on one thread: what a defender could pin on the C2 at each step. It is not a complete list of command and control and shouldn’t be read as one. Whole families, protocols and operator habits are missing. I’m writing a separate post on C2 servers and how they escalated and advanced over the years, and the full picture belongs there.
Read it as a pattern, which is my interpretation. Until 2014 the thing to pin changed but always lived in the malware’s own design: a port, a channel, a domain, an algorithm. From Malleable C2 on, the operator decides, and from the leaks on, the operator can be anyone. The part that no longer changes is how the foothold behaves.
6. Takedowns change the numbers, not the tool
In March 2023 a US court order let Microsoft, Fortra and Health-ISAC act against C2 infrastructure. Operation Morpheus ran from 24 to 28 June 2024: 593 servers taken down out of 690 flagged IPs in 27 countries. Fortra says unauthorized copies fell by about 80% over two years and that it seized more than 200 domains.
Good results, and the feed above still has 1,289 Cobalt Strike indicators in two days. A takedown retires a server. It doesn’t retire the copy of the tool that built it.
7. Matanbuchus: the rental that hands off the beacon
Matanbuchus is loader as a service. BelialDemon advertised it in February 2021 at $2,500 rental. In June 2022 Cyble reported a campaign (ZIP, HTML, MSI, then a main.dll stager) where the payload fetched two Cobalt Strike beacons from the C2.
Version 3.0 turned up in July 2025 at $10,000 for the HTTP build and $15,000 for DNS. Delivery moved to a fake IT call on Teams followed by Quick Assist, the traffic is ChaCha20 over Protobuf, and ThreatLabz sees it behaving like a pre-ransomware implant. The follow-on payloads Zscaler named were Rhadamanthys and NetSupport RAT. I’m not claiming 3.0 drops Cobalt Strike unless my own samples show it.
For the IOC question the point is the same either way. A rented loader gives every customer the same stager and each customer picks their own second stage. One stager, many beacons, many unrelated operators.
8. Shellter Elite: a license leak, not a crack
Shellter Elite 11.0 came out on 16 April 2025. By late April Elastic Security Labs was seeing it wrap Lumma, Arechclient2 and Rhadamanthys. Every sample carried the same license expiry timestamp, 2026-04-17 19:17:24 UTC, which means one copy was behind all of it. Shellter confirmed that a customer had leaked their copy, and shipped 11.1 to vetted customers only.
So this one is a licensed copy that left through a customer, not a patched binary posted to a forum. Elastic’s report names infostealers and doesn’t mention Cobalt Strike. Shellter’s job is to hide a payload from AV and EDR, and the reasoning for putting it in a Cobalt Strike post is that it sits in the same chain: a loader, an evasion wrapper, a beacon.
9. NightRaider and the purchased license
NightRaider is a persona on a Russian-language cybercrime forum. Botcrawl reported an EDR killer for $5,000 in November 2025, with a claimed Microsoft-signed driver. In April 2026 Sophos CTU saw an advert for an updated Cobalt Strike with a REST API and an MCP server. Sophos hadn’t validated any of the claimed capabilities, and neither have I.
Two things here are mine, and I have the evidence for both. NightRaider provides EDR test panels, a place to run a build against current EDR products before it ships. The panel is mentioned in a thread on the Exploit forum, a paid, semi-private board, and the products it names are CrowdStrike, Sophos, Trellix and ESET EDR. And NightRaider is creating ad hoc companies to buy Cobalt Strike and Nighthawk, the commercial C2 and penetration testing toolkits.
MDSec’s own Nighthawk statement describes this route. It checks the registered company, the end-user location and the ultimate beneficial owner, requires three seats, has no self-hosted trials, and watermarks each build. It also says plainly that this does not stop bad actors setting up shell companies or using resellers. When it wrote that in November 2022 it had seen no abuse. Sophos made the same point about Brute Ratel in 2023: actors who can hide a purchase behind a front company get the newer versions.
My reading, which is inference and not something the sources say:
- A copy bought through a front company isn’t cracked, so the patched-watermark tell doesn’t fire.
- Its watermark leads to the front company, not to the operator.
- It’s current, because the buyer paid for updates, which breaks the “abused copies run at least one release behind” assumption Google’s signatures lean on.
The EDR test panel is the other half of the same story. A seller who can test builds against current EDR products before they ship is selling the iteration loop that makes new builds land.
10. Recognising implants
Antivirus and implant detection are two different jobs, and Cobalt Strike is where the gap shows.
Context
An implant is the code left running on a compromised host that the operator controls remotely: Beacon, a RAT client, a loader’s second stage. Detecting an implant means noticing a live host under someone else’s control, whether or not any file on disk is known to be bad.
Antivirus and anti-malware ask whether a file is known bad. Against a stock build that works, which is what Google’s rules and every vendor’s signatures are for. It stops working at the three points this post has covered. The loader gets rebuilt, which is what the Artifact Kit is for. The beacon is loaded into memory and, as Elastic puts it, never touches disk in a form you can sign, so Elastic writes its signatures for the decrypted payload in memory instead. And the operator spends most of the time using tools already on the machine.
Implant detection asks a different question: is this host behaving as if someone else is driving it? It looks at what stays the same when the file changes. Sophos found Cobalt Strike leaning on rundll32.exe for command execution, and spreading by writing a service executable with a seven-character name to the ADMIN$ share. Add the fork and run pattern from section 3, named pipes, access to LSASS, and memory that is executable but not backed by a file. Even Beacon’s sleep obfuscation left its code section readable in 2021, Elastic noted, which is why YARA over memory still finds it.
| Antivirus and anti-malware | Implant detection (EDR, memory, behaviour) | Network analysis | |
|---|---|---|---|
| The question | Is this file known bad? | Is this host behaving as if someone else is driving it? | Is this host talking like it is being controlled? |
| It looks at | Files on disk, scripts, sometimes memory at load time. Signatures and models. | Process trees, command lines, injection, named pipes, credential access, memory regions. | DNS, proxy and TLS metadata, flows, timing. |
| Good at | Stock builds, known loaders, commodity RATs. | Hands-on activity, in-memory beacons, post-exploitation. | Beaconing, shared infrastructure, hosts with no agent. |
| Misses | Rebuilt loaders, in-memory beacons, anything new. | Quiet operators, hosts with no agent. | Encrypted content, traffic shaped to look ordinary, short sessions. |
Context
JARM, published by Salesforce in 2021, sends 10 specially built TLS hellos to a server and hashes the answers into a 62-character fingerprint. Servers configured the same way answer the same way, so a JARM value clusters command-and-control infrastructure, Cobalt Strike servers among it. It identifies a configuration, not an owner.
Network analysis covers what the host agent can’t, and the other way round. A beacon checks in on a rhythm, and a rhythm is hard to hide: a regular interval with some jitter, a destination few other hosts talk to, URIs and headers from a profile nobody else on your network uses, a TLS certificate left on its default. Researchers cluster servers by fingerprint (JARM, above), Recorded Future used the default certificate to find them, and NCC used the checksum8 behaviour of default team servers to pull configs at scale. Each signal is weak alone, and a well-built profile removes some of them. Together, over weeks of logs, they are hard to avoid. You can try the timing side in this site’s Beacon hunter lab, which hides three beacons and a DNS tunnel in one synthetic hour of logs.
Recommendations at base level
- Keep antivirus on, with tamper protection, and read a clean scan as “not known bad”. It still removes the stock builds and the commodity loaders for free.
- Log process creation with command lines, named pipe events and LSASS access on every endpoint, through an EDR or at minimum Sysmon. Alert on
rundll32.exerun with no arguments that then spawns or injects, on service installs from admin shares, and on unexpected handles tolsass.exe. - Turn on LSA protection and Credential Guard, and keep administrator credentials off workstations. They take away the easy credential route (section 3).
- Log DNS, proxy and TLS metadata at egress (destination, SNI, certificate, client fingerprint) and flow data, and keep it for weeks, not days. A slow beacon needs the history.
- Hunt for rhythm in those logs: hosts talking to one rare destination at a regular interval, with or without jitter. Start with the proxy and DNS logs.
- Scan memory, not only files. Run Google’s and Elastic’s YARA sets over memory dumps and suspect files, and remember Google’s set stops at 4.7.
- Restrict egress, so servers and workstations reach only what they need, and treat newly registered or uncategorised domains with suspicion.
- Write the playbook before you need it: isolate the host, capture memory, reset credentials, and look for the same config and for SMB or WinRM movement elsewhere.
The base-level stack
Base level
Base level is the floor, not the ceiling: the controls that make a stock or lightly modified Cobalt Strike show up at all. A mature program adds memory forensics on demand, packet capture on key segments, deception, a detection engineering practice and regular purple-team testing. This section covers only the floor.

Read it from the bottom. A stock build is stopped at layer 2. A rebuilt, in-memory beacon slips past layer 2 and shows up only in layers 3 and 4, which is the whole reason the layers above antivirus exist.
11. What I’d do with the IOCs
- Treat C2 IPs and domains as short-lived. Expire them.
- Pivot on the config: watermark, profile fields, sleep and jitter, C2 ports. Clusters survive when servers don’t.
- Triage a hit by what the operator did, not by the family: credential access, lateral movement and a rebuilt loader are a different incident from a default team server that never got past one host.
- Keep Google’s YARA set, and remember it stops at 4.7 on purpose, so a current copy won’t match it. Add detection on the stage before the beacon (the loader), where the rental model concentrates.
- Don’t read a Cobalt Strike hit as attribution.
Mapping those clusters, and the personas behind them, is graph work. I do mine in NocTORnal, the social network analysis software I write, on GitHub.
Public rules exist for both families. They are version-specific, and I compile-checked every one but haven’t run them against samples, so test them on your own corpus before you trust a miss.
| Family | Rule set | What it covers |
|---|---|---|
| Cobalt Strike | Google Cloud Threat Intelligence (Apache 2.0) | Leaked and cracked releases up to 4.7, one rule per component and version range |
| Cobalt Strike | Elastic | Post-exploitation modules, reflective loader, sleep obfuscation, for file and memory scans |
| Cobalt Strike | signature-base | Google’s set merged, plus Avast, JPCERT, evasive-beacon and sleep mask rules |
| Matanbuchus | Elastic (Mar 2022) | Persistence strings and byte patterns from the original builds |
| Matanbuchus | CyberArk (2022) | The initial-stage and main-stage DLLs |
| Matanbuchus | BitSight on YARAhub (Jul 2022) | Loader and core, by API-hash constants and stack strings |
| Matanbuchus | RussianPanda | The 3.0 loader, the only rule here labelled for it |
References
- BleepingComputer, alleged source code of Cobalt Strike shared online.
- Security Affairs, the same leak.
- Google Cloud, making Cobalt Strike harder for threat actors to abuse.
- Bitdefender, 34 cracked versions found in the wild, Google warns (21 Nov 2022).
- NCC Group, mining data from Cobalt Strike beacons.
- Unit 42, public Cobalt Strike profiles.
- The Record, Fortra’s 80% figure.
- Security Affairs, Operation Morpheus.
- Unit 42, Matanbuchus.
- The Hacker News, Cyble’s June 2022 report.
- Zscaler ThreatLabz, Matanbuchus 3.0.
- Morphisec, Matanbuchus 3.0.
- Elastic Security Labs, Taking SHELLTER.
- SecurityWeek, Shellter used in malware attacks.
- Botcrawl, NightRaider EDR killer.
- Sophos, AI in the underground.
- MDSec, Nighthawk, with great power comes great responsibility.
- SecurityWeek, Proofpoint on Nighthawk.
- MITRE ATT&CK, Cobalt Strike (S0154).
- Fortra, Payload artifacts and anti-virus evasion, and Cobalt Strike 4.1, the mark of injection.
- Splunk, You bet your LSASS: hunting LSASS access (Apr 2022).
- Microsoft Learn, Configure added LSA protection.
- Sophos, 2022 threat report.
- Proofpoint, Cobalt Strike: favorite tool from APT to crimeware (Jun 2021), and BankInfoSecurity, attackers increasingly using Cobalt Strike.
- Sophos, The phantom menace: Brute Ratel remains rare and targeted (2023).
- Recorded Future, a multi-method approach to identifying rogue Cobalt Strike servers.
- Elastic, Detecting Cobalt Strike with memory signatures (Mar 2021).
- Sophos, Detecting Cobalt Strike in cybercrime attacks.
- Salesforce Engineering, Easily identify malicious servers on the internet with JARM (Nov 2021).
- BleepingComputer, hacker infects 18,000 script kiddies with fake malware builder, on CloudSEK’s research, and CloudSEK, uncovering a trojanized XWorm RAT builder.
- Cobalt Strike blog, Cobalt Strike 2.0: Malleable Command and Control, and Fortra, about Cobalt Strike.
- Wikipedia, Back Orifice, Botnet and Conficker, for the early dates in the chronology.
- Security Affairs, APT 29 use Twitter to control its Hammertoss data stealer, on FireEye’s July 2015 report.
- abuse.ch, ThreatFox, the source of the 48-hour indicator counts.