Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Cobalt Strike Operators Leverage PowerShell Loaders Across Chinese, Russian, and Global Infrastructure

Summary

A PowerShell shellcode loader found in a Chinese open directory executes in memory, fetches stage two from Baidu Cloud Functions, and beacons to Cobalt Strike infrastructure in Russia.
Published
Collected

original ↗