{"schema":"aeternae-malware-metadata/v1","generated_at":"2026-10-08T09:16:22+00:00","total_matching":1,"page":1,"page_size":200,"records":[{"id":"6ac9c1ae3d1bb13e1fff65e533f0075584e2fe573227781cbacfc89cff20006d","kind":"reference","title":"Cobalt Strike","family":"Cobalt Strike","category":"Malware intelligence","summary":"Malware galaxy based on Malpedia archive. | Cobalt Strike is a paid penetration testing product that allows an attacker to deploy an agent named 'Beacon' on the victim machine. Beacon includes a wealth of functionality to the attacker, including, but not limited to command execution, key logging, file transfer, SOCKS proxying, privilege escalation, mimikatz, port scanning and lateral movement. Bea","first_seen":1759241384,"last_seen":1759241384,"created_at":1791440284,"updated_at":1791440284,"source_count":1,"data":{"context":"2025/09/uat-8099-chinese-speaking-cybercrime-group-seo-fraud.json","tags":["misp:galaxy-name=\"Malpedia\"","misp:galaxy-type=\"malpedia\"","misp-galaxy:malpedia=\"Cobalt Strike\""],"aliases":[],"references":["https://github.com/Cisco-Talos/IOCs/blob/main/2025/09/uat-8099-chinese-speaking-cybercrime-group-seo-fraud.json"],"filenames":[],"features":[],"related_cves":[],"labels":["Cobalt Strike"]},"observations":[{"source_id":"talos_ioc","source_url":"https://github.com/Cisco-Talos/IOCs/blob/main/2025/09/uat-8099-chinese-speaking-cybercrime-group-seo-fraud.json","source_label":"Cobalt Strike","evidence_class":"provider_reported","confidence":null,"observed_at":1759241384,"fetched_at":1791440284,"data":{"context":"2025/09/uat-8099-chinese-speaking-cybercrime-group-seo-fraud.json","tags":["misp:galaxy-name=\"Malpedia\"","misp:galaxy-type=\"malpedia\"","misp-galaxy:malpedia=\"Cobalt Strike\""],"aliases":[],"references":["https://github.com/Cisco-Talos/IOCs/blob/main/2025/09/uat-8099-chinese-speaking-cybercrime-group-seo-fraud.json"],"family":"Cobalt Strike"}}],"indicators":[]}]}