Sunday, September 13, 2026

Hackers Deploy Cobalt Strike Beacon Using GitHub and Social Media

A sophisticated cyberattack campaign disrupted the Russian IT industry and entities in several other countries, leveraging advanced evasion techniques to deploy the notorious Cobalt Strike Beacon.

Attackers ingeniously concealed payload information within user profiles on platforms like GitHub, Microsoft Learn Challenge, Quora, and Russian social networks, blending malicious data into legitimate user-generated content to bypass security detections.

This approach allowed them to construct a complex execution chain for Cobalt Strike, a widely used post-exploitation tool.

The campaign peaked in November and December 2024, persisted until April 2025, and resumed after a two-month hiatus with minimally altered malware variants.

Kaspersky’s security solutions identified the threats under verdicts such as HEUR:Trojan.Win64.Agent.gen, HEUR:Trojan.Win64.Kryptik.gen, HEUR:Trojan.WinLNK.Starter.gen, MEM:Trojan.Multi.Cobalt.gen, and HEUR:Trojan.Win32.CobaltStrike.gen.

Targets Russian IT Sector

The initial infection vector relied on spear-phishing emails masquerading as communications from major state-owned oil and gas companies, enticing victims with feigned interest in their products to prompt attachment openings.

Cobalt Strike Beacon
Sample spear phishing email

These emails contained RAR archives structured with a malicious LNK file named “Требования.lnk,” decoy PDFs like “Company Profile.pdf” and “List of requirements.pdf,” and a hidden directory holding executables disguised as PDFs.

Upon execution, the LNK file copied and renamed these to “%public%\Downloads” as “nau.exe” (a legitimate BugSplat crash reporting utility, originally BsSndRpt.exe) and “BugSplatRc64.dll” (the malicious DLL), then launched “nau.exe.”

Cobalt Strike Beacon
Process flow diagram for nau.exe

This exploited DLL hijacking (MITRE T1574.001), forcing the utility to load the rogue DLL instead of its legitimate counterpart.

Payload Delivery

The malicious DLL employed dynamic API resolution (MITRE T1027.007) via a custom hashing algorithm akin to CRC, with hashes XOR-encrypted and addresses cleared post-call to evade static analysis.

It hooked API functions like MessageBoxW within the legitimate process, redirecting calls to a custom function that initiated a two-stage shellcode loading process.

This function fetched HTML from encrypted URLs, such as profiles on techcommunity.microsoft.com or quora.com, extracting base64-encoded, XOR-encrypted strings that revealed further download links from GitHub repositories.

The shellcode, a reflective loader (MITRE T1620), injected Cobalt Strike Beacon into memory, establishing communication with command-and-control servers like moeodincovo[.]com/divide/mail/SUVVJRQO8QRC.

Attribution links this campaign to patterns observed in the EastWind APT operation, including XOR-encrypted URLs in platform profiles and overlapping targets in Russian IT firms.

While primarily affecting large and medium-sized Russian businesses, infections extended to China, Japan, Malaysia, and Peru.

The attackers created dedicated accounts (MITRE T1585.001) but could exploit comments on legitimate posts for broader concealment.

This campaign highlights the growing use of DLL hijacking and legitimate platforms for malware staging, underscoring the need for robust defenses.

Organizations should monitor infrastructure, deploy advanced security solutions for email-based threats, conduct cybersecurity training, and use endpoint detection systems to block early-stage attacks. Detection indicators include unsigned “BugSplatRc64.dll” files or renamed BugSplat utilities.

Indicators of Compromise (IOCs)

CategoryIOC
LNK30D11958BFD72FB63751E8F8113A9B04
92481228C18C336233D242DA5F73E2D5
Legitimate BugSplat.exe633F88B60C96F579AF1A71F2D59B4566
DLL2FF63CACF26ADC536CD177017EA7A369
08FB7BD0BB1785B67166590AD7F99FD2
02876AF791D3593F2729B1FE4F058200
F9E20EB3113901D780D2A973FF539ACE
B2E24E061D0B5BE96BA76233938322E7
15E590E8E6E9E92A18462EF5DFB94298
66B6E4D3B6D1C30741F2167F908AB60D
ADD6B9A83453DB9E8D4E82F5EE46D16C
A02C80AD2BF4BFFBED9A77E9B02410FF
672222D636F5DC51F5D52A6BD800F660
2662D1AE8CF86B0D64E73280DF8C19B3
4948E80172A4245256F8627527D7FA96
URLhxxps://techcommunity[.]microsoft[.]com/users/kyongread/2573674
hxxps://techcommunity[.]microsoft[.]com/users/mariefast14/2631452
hxxps://raw[.]githubusercontent[.]com/fox7711/repos/main/1202[.]dat
hxxps://my[.]mail[.]ru/mail/nadezhd_1/photo/123
hxxps://learn[.]microsoft[.]com/en-us/collections/ypkmtp5wxwojz2
hxxp://10[.]2[.]115[.]160/aa/shellcode_url[.]html
hxxps://techcommunity[.]microsoft[.]com/t5/user/viewprofilepage/user-id/2548260
hxxps://techcommunity[.]microsoft[.]com/t5/user/viewprofilepage/user-id/2631452
hxxps://github[.]com/Mashcheeva
hxxps://my[.]mail[.]ru/mail/veselina9/photo/mARRy
hxxps://github[.]com/Kimoeli
hxxps://www[.]quora[.]com/profile/Marieformach
hxxps://moeodincovo[.]com/divide/mail/SUVVJRQO8QRC

Find this News Interesting! Follow us on Google NewsLinkedIn, & X to Get Instant Updates!

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Related Articles

Recent News