Google Releases YARA Rules to Disrupt Cobalt Strike Abuse

Share:

The popular pen-testing tool is often cracked and repurposed by threat actors. Google now has a plan to address that.

Cobalt Strike, a popular red-team tool for detecting software vulnerabilities, has been repurposed by cyberattackers so frequently that publisher Fortra instituted a system for vetting potential buyers. In response, malicious actors have switched to using cracked versions of the software distributed online like any other hacker tool. Google’s Cloud Security team has now come up with a way to counteract these shady uses while not interfering with legitimate ones: version detection.

Threat actors have easy access to Cobalt Strike through pirating, but these illegitimate versions usually cannot be updated, wrote Greg Sinclair, security engineer for cloud threat intelligence at Google. That provides Google researchers with a way to spot potentially malicious use by identifying the version of the software being used, and flagging anything earlier than the current version.

To identify the version, Google researchers analyzed the Cobalt Strike JAR files from the past 10 years and generated signatures for the various components — 165 in all. Then the team bundled the signatures into a VirusTotal collection and released them as open source YARA rules on GitHub.

“Since many threat actors rely on cracked versions of Cobalt Strike to advance their cyberattacks, we hope that by disrupting its use we can help protect organizations, their employees, and their customers around the globe,” Sinclair wrote.

Earlier in November, Google Cloud Threat Intelligence released on GitHub a similar set of signatures to detect Sliver, as Bleeping Computer pointed out. The command-and-control framework has been supplanting Cobalt Strike as the repurposed security tool of choice by some threat actors.

https://www.darkreading.com/dr-tech/google-releases-yara-rules-to-disrupt-cobalt-strike-abuse

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:50 pm, Jul 11, 2025
weather icon 23°C
L: 21° | H: 23°
clear sky
Humidity: 64 %
Pressure: 1018 mb
Wind: 6 mph ESE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 1%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:56 am
Sunset: 9:15 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
21° | 23°°C 0 mm 0% 10 mph 65 % 1018 mb 0 mm/h
Sun Jul 13 10:00 pm
weather icon
17° | 29°°C 0 mm 0% 7 mph 66 % 1015 mb 0 mm/h
Mon Jul 14 10:00 pm
weather icon
19° | 28°°C 0 mm 0% 14 mph 71 % 1017 mb 0 mm/h
Tue Jul 15 10:00 pm
weather icon
15° | 25°°C 0 mm 0% 13 mph 68 % 1020 mb 0 mm/h
Wed Jul 16 10:00 pm
weather icon
18° | 25°°C 1 mm 100% 13 mph 83 % 1019 mb 0 mm/h
Tomorrow 1:00 am
weather icon
20° | 23°°C 0 mm 0% 3 mph 64 % 1018 mb 0 mm/h
Tomorrow 4:00 am
weather icon
17° | 21°°C 0 mm 0% 4 mph 63 % 1018 mb 0 mm/h
Tomorrow 7:00 am
weather icon
19° | 20°°C 0 mm 0% 5 mph 65 % 1018 mb 0 mm/h
Tomorrow 10:00 am
weather icon
26° | 26°°C 0 mm 0% 6 mph 44 % 1017 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
29° | 29°°C 0 mm 0% 6 mph 32 % 1016 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
29° | 29°°C 0 mm 0% 10 mph 30 % 1014 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
25° | 25°°C 0 mm 0% 9 mph 41 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
21° | 21°°C 0 mm 0% 6 mph 55 % 1015 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€100,498.22
1.26%
Ethereum(ETH)
€2,518.35
-0.75%
Tether(USDT)
€0.86
0.03%
XRP(XRP)
€2.29
5.30%
Solana(SOL)
€137.69
-2.05%
USDC(USDC)
€0.86
0.02%
Dogecoin(DOGE)
€0.170079
3.16%
Shiba Inu(SHIB)
€0.000011
-0.64%
Pepe(PEPE)
€0.000010
-1.71%
Peanut the Squirrel(PNUT)
€0.246234
7.19%
Scroll to Top