Commercial and open-source command-and-control (C2) frameworks have become a staple in most adversary toolkits, with Cobalt Strike (CS) being one of the most popular. Such frameworks are often leveraged by threat actors to stage and conduct post-exploitation attacks in compromised client estates.
The prevalence of Cobalt Strike usage in attacks has precipitated a drive towards the creation of improved detection capabilities against it. Conversely, adversaries have responded to this by implementing their own detection evasion strategies. The most common of these include adding complexity to the auto-generated beacon or stager payloads via the utilization of packers, crypters, loaders, or similar techniques. While some threat actors rely on commercial crypters, others opt to develop their own custom crypters or take existing custom crypters into use.
During our investigations through several human-operated intrusions that resembled precursors to ransomware deployments, we came across an interesting Cobalt Strike beacon loader that leveraged DLL side-loading, which we’re tracking as SILKLOADER. By taking a closer look at the loader, we found several activity clusters leveraging this loader within the Russian as well as Chinese cybercriminal ecosystems.
In this report we share technical analysis of SILKLOADER and highlight notable activity clusters where it was seen in our investigations.
What next?
Discover WithSecure™ Elements Exposure Management.
– No credit card required. No obligations.No complexity.
Lumma is an information stealer that the WithSecure Detection and Response Team (DRT) have encountered several times. It has seen wider use over the past couple of years, and makes for an interesting threat to monitor.
Le musée est situé au siège d’Helsinki de WithSecure et accueille les visiteurs sur rendez-vous. Remplissez le formulaire ci-dessous et notre équipe vous contactera pour organiser votre visite.
À quoi vous attendre lors de votre visite
Vivez l’expérience de neuf œuvres saisissantes qui rendent des cybermenaces complexes tangibles, accessibles et impossibles à ignorer.
Découvrez comment le malware a évolué sur trois décennies à travers un art créé en collaboration avec des chercheurs de premier plan en cybersécurité.
Comprenez pourquoi la cybersécurité concerne chacun d’entre nous, sans aucune connaissance technique requise.