Google veröffentlicht YARA-Regeln zur Unterbindung des Missbrauchs von Kobaltstreiks

Teilen:

The popular pen-testing tool is often cracked and repurposed by threat actors. Google now has a plan to address that.

Cobalt Strike, a popular red-team tool for detecting software vulnerabilities, has been repurposed by cyberattackers so frequently that publisher Fortra instituted a system for vetting potential buyers. In response, malicious actors have switched to using cracked versions of the software distributed online like any other hacker tool. Google’s Cloud Security team has now come up with a way to counteract these shady uses while not interfering with legitimate ones: version detection.

Threat actors have easy access to Cobalt Strike through pirating, but these illegitimate versions usually cannot be updated, schrieb Greg Sinclair, security engineer for cloud threat intelligence at Google. That provides Google researchers with a way to spot potentially malicious use by identifying the version of the software being used, and flagging anything earlier than the current version.

To identify the version, Google researchers analyzed the Cobalt Strike JAR files from the past 10 years and generated signatures for the various components — 165 in all. Then the team bundled the signatures into a VirusTotal collection and released them as open source YARA rules on GitHub.

“Since many threat actors rely on cracked versions of Cobalt Strike to advance their cyberattacks, we hope that by disrupting its use we can help protect organizations, their employees, and their customers around the globe,” Sinclair wrote.

Earlier in November, Google Cloud Threat Intelligence released on GitHub a similar set of signatures to detect Sliver, as Bleeping Computer pointed out. The command-and-control framework has been supplanting Cobalt Strike as the repurposed security tool of choice by some threat actors.

https://www.darkreading.com/dr-tech/google-releases-yara-rules-to-disrupt-cobalt-strike-abuse

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
10:41 am, Juli 12, 2025
Wetter-Symbol 26°C
L: 25° | H: 28°
klarer Himmel
Luftfeuchtigkeit: 52 %
Druck: 1017 mb
Wind: 7 mph ESE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 1%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:57 am
Sonnenuntergang: 9:14 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
25° | 28°°C 0 mm 0% 10 mph 47 % 1017 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
17° | 28°°C 0 mm 0% 6 mph 64 % 1015 mb 0 mm/h
Mo. Juli 14 10:00 pm
Wetter-Symbol
19° | 26°°C 0 mm 0% 17 mph 67 % 1015 mb 0 mm/h
Di. Juli 15 10:00 pm
Wetter-Symbol
14° | 22°°C 0 mm 0% 15 mph 69 % 1016 mb 0 mm/h
Mi. Juli 16 10:00 pm
Wetter-Symbol
16° | 28°°C 0 mm 0% 12 mph 74 % 1017 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
27° | 28°°C 0 mm 0% 7 mph 47 % 1017 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
29° | 30°°C 0 mm 0% 10 mph 36 % 1015 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
26° | 26°°C 0 mm 0% 10 mph 37 % 1014 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 6 mph 47 % 1015 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 4 mph 60 % 1015 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 5 mph 64 % 1014 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 5 mph 59 % 1013 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
23° | 23°°C 0 mm 0% 5 mph 47 % 1013 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€100,937.02
-0.42%
Ethereum(ETH)
€2,541.20
-1.74%
XRP(XRP)
€2.40
8.16%
Fesseln(USDT)
€0.86
0.00%
Solana(SOL)
€139.03
-1.50%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.171828
1.52%
Shiba Inu(SHIB)
€0.000011
-0.36%
Pepe(PEPE)
€0.000010
-3.14%
Peanut das Eichhörnchen(PNUT)
€0.246209
7.19%
Nach oben scrollen