Cobalt Strike Operators Leverage PowerShell Loaders Across Chinese, Russian, and Global Infrastructure
hunt.io | blog | #cloud | #c2 | #powershell | #cobalt-strike | #open-directory | #shellcode-loader | #attacker-infrastructure
Summary
A PowerShell shellcode loader found in a Chinese open directory executes in memory, fetches stage two from Baidu Cloud Functions, and beacons to Cobalt Strike infrastructure in Russia.
- Published
- Collected
Skip to content