ATT&CKSoftwareCobalt Strike

Cobalt Strike

S0154

Malware.View on attack.mitre.org

About this malware

Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.

In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.

Techniques used73

Procedure examples73

TechniqueProcedure example
T1001.003
Protocol or Service Impersonation

Cobalt Strike can leverage the HTTP protocol for C2 communication, while hiding the actual data in either an HTTP header, URI parameter, the transaction body, or appending it to the URI. Cobalt Strike has also added Host: ocsp.verisign.com to HTTP headers to mimic Online Certificate Status Protocol (OCSP) traffic.

T1003.001
LSASS Memory

Cobalt Strike can spawn a job to inject into LSASS memory and dump password hashes.

T1003.002
Security Account Manager

Cobalt Strike can recover hashed passwords.

T1005
Data from Local System

Cobalt Strike can collect data from a local system.

T1007
System Service Discovery

Cobalt Strike can enumerate services on compromised hosts.

T1012
Query Registry

Cobalt Strike can query HKEY_CURRENT_USER\Software\Microsoft\Office\<Excel Version>\Excel\Security\AccessVBOM\ to determine if the security setting for restricting default programmatic access is enabled.

T1016
System Network Configuration Discovery

Cobalt Strike can determine the NetBios name and the IP addresses of targets machines including domain controllers.

T1018
Remote System Discovery

Cobalt Strike uses the native Windows Network Enumeration APIs to interrogate and discover targets in a Windows Active Directory network.

T1021.001
Remote Desktop Protocol

Cobalt Strike can start a VNC-based remote desktop server and tunnel the connection through the already established C2 channel.

T1021.002
SMB/Windows Admin Shares

Cobalt Strike can use Window admin shares (C$ and ADMIN$) for lateral movement.

T1021.003
Distributed Component Object Model

Cobalt Strike can deliver Beacon payloads for lateral movement by leveraging remote COM execution.

T1021.004
SSH

Cobalt Strike can SSH to a remote service.

T1021.006
Windows Remote Management

Cobalt Strike can use WinRM to execute a payload on a remote host.

T1027
Obfuscated Files or Information

Cobalt Strike can hash functions to obfuscate calls to the Windows API and use a public/private key pair to encrypt Beacon session metadata.

T1027.005
Indicator Removal from Tools

Cobalt Strike includes a capability to modify the Beacon payload to eliminate known signatures or unpacking methods.

View all 73 procedure examples

Groups that use it30

Show 6 more

Campaigns6

References1

  1. cobaltstrike manual Open source
    Strategic Cyber LLC. (2017, March 14). Cobalt Strike Manual. Retrieved May 24, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.