Cobalt Strike Beacon delivered via GitHub and social media


n the latter half of 2024, the Russian IT industry, alongside a number of entities in other countries, experienced a notable cyberattack. The attackers employed a range of malicious techniques to trick security systems and remain undetected.

To bypass detection, they delivered information about their payload via profiles on both Russian and international social media platforms, as well as other popular sites supporting user-generated content. The samples Kaspersky security researchres analyzed communicated with GitHub, Microsoft Learn Challenge, Quora, and Russian-language social networks. The attackers thus aimed to conceal their activities and establish a complex execution chain for the long-known and widely used Cobalt Strike Beacon.

Read more…
Source: Kaspersky


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • What the First Autonomous Ransomware Case Confirms

    July 24, 2026

    Security researchers have documented an AI agent running a full ransomware operation on its own against a live production target, planning, adapting, and executing every step from the first exploit through data destruction. This is early real-world evidence of the shift to autonomous criminal operations that our research forecast. Agent-run attacks change what defenders can rely ...

  • CISA has expanded the scope of its alert on Iranian-affiliated hackers attacking critical infrastructure

    July 23, 2026

    The US Cybersecurity and Infrastructure Security Agency (CISA) has expanded the scope of its alert on Iranian-affiliated hackers attacking critical infrastructure, including water and energy facilities. The original advisory focused on programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley. The update warns that the activity may also target devices from Schneider Electric, Siemens, “and potentially other branded/manufactured PLCs.” The conflict between ...

  • Millions of cars could be tracked and unlocked by a hidden security flaw

    July 23, 2026

    A car alarm vendor’s coding mistake has left millions of vehicles vulnerable to theft and location tracking. Thanks to the way dealers sell car alarms, many affected drivers don’t even know they have one installed. The device is the KARR Security System, a Bluetooth-enabled aftermarket alarm built by Acrisure Protection Group. It’s installed by dealers, primarily ...

  • Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite

    July 23, 2026

    A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see Cybersecurity industry tracking), primarily as ...

  • Experts warn hackers could shut down entire power grids by hijacking cloud accounts

    July 21, 2026

    Whenever an AI data center thinks really, really hard, it can increase its power consumption so much to trigger disruptions and possibly even blackouts and gear malfunctions. So, is it possible for a malicious actor to trigger this scenario deliberately, in order to cause physical harm? Multiple researchers from the Zhejiang University in Hangzhou, China, wrote ...

  • Inside an Exposed WebDAV Malware Delivery Lab

    July 20, 2026

    An MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematically tested delivery paths, social engineering lures, and WebDAV execution methods. Our analysis reveals an ...