Product
high
threat
Cobalt Strike Command and Control Beacon Detection
1 rule 2 TTPsAdversaries, notably FIN7, deploy Cobalt Strike beacons on compromised systems to establish command and control (C2) channels, utilizing specific network activity algorithms and domain naming conventions for communication over protocols like HTTP or TLS, posing a critical risk of further compromise and data exfiltration.
Cobalt Strike
FIN7
+2
command-and-control
malware
network-traffic
cobalt-strike
threat-detection
1r
2t
high
threat
FrostyNeighbor Targets Ukraine with Updated PicassoLoader Chain
2 rules 3 TTPs 5 CVEs 16 IOCsThe FrostyNeighbor threat actor is targeting Ukrainian governmental organizations with spearphishing emails containing malicious PDFs that deliver a JavaScript dropper (PicassoLoader) and ultimately a Cobalt Strike beacon.
PoC
Cobalt Strike +8
FrostyNeighbor
cyberespionage
cobaltstrike
picassoloader
ukraine
2r
3t
5c
16i
updated