Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 15, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 15, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 15, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 15, 2025

      Intel’s latest Arc graphics driver is ready for DOOM: The Dark Ages, launching for Premium Edition owners on PC today

      May 15, 2025

      NVIDIA’s drivers are causing big problems for DOOM: The Dark Ages, but some fixes are available

      May 15, 2025

      Capcom breaks all-time profit records with 10% income growth after Monster Hunter Wilds sold over 10 million copies in a month

      May 15, 2025

      Microsoft plans to lay off 3% of its workforce, reportedly targeting management cuts as it changes to fit a “dynamic marketplace”

      May 15, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      A cross-platform Markdown note-taking application

      May 15, 2025
      Recent

      A cross-platform Markdown note-taking application

      May 15, 2025

      AI Assistant Demo & Tips for Enterprise Projects

      May 15, 2025

      Celebrating Global Accessibility Awareness Day (GAAD)

      May 15, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Intel’s latest Arc graphics driver is ready for DOOM: The Dark Ages, launching for Premium Edition owners on PC today

      May 15, 2025
      Recent

      Intel’s latest Arc graphics driver is ready for DOOM: The Dark Ages, launching for Premium Edition owners on PC today

      May 15, 2025

      NVIDIA’s drivers are causing big problems for DOOM: The Dark Ages, but some fixes are available

      May 15, 2025

      Capcom breaks all-time profit records with 10% income growth after Monster Hunter Wilds sold over 10 million copies in a month

      May 15, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Law Enforcement and Private Sector Team Up to Disrupt Cobalt Strike Abuse

    Law Enforcement and Private Sector Team Up to Disrupt Cobalt Strike Abuse

    July 3, 2024

    In a coordinated takedown, law enforcement and cybersecurity firms joined forces to cripple cybercriminals’ misuse of a legitimate security tool – Cobalt Strike. The week-long operation, codenamed MORPHEUS and spearheaded by UK’s National Crime Agency, targeted unlicensed versions of Cobalt Strike used to infiltrate victim networks.

    Europol, which helped coordinate the operation involving authorities from six other countries, said a total of 690 IP addresses linked to criminal activity were flagged. By the end of the week, over 85% (593) of these addresses associated with unlicensed Cobalt Strike instances were disabled by internet service providers (ISPs) in 27 countries.

    Cobalt Strike: Double-Edged Sword

    Cobalt Strike, a commercially available tool by Fortra, is used by ethical hackers for penetration testing – simulating cyberattacks to identify vulnerabilities in a network’s defenses. However, in the hands of malicious actors, unlicensed versions of Cobalt Strike transform into a powerful weapon.

    “Since the mid 2010’s, pirated and unlicensed versions of the software downloaded by criminals from illegal marketplaces and the dark web have gained a reputation as the ‘go-to’ network intrusion tool for those seeking to build a cyberattack, allowing them to deploy ransomware at speed and at scale.” – UK’s NCA

    Cybercriminals typically deploy Cobalt Strike through spear phishing emails, tricking victims into clicking malicious links or opening infected attachments. Once a victim clicks, a “Beacon” is installed, granting the attacker remote access to the compromised system. This access allows them to steal data, through infostealers, or launch further attacks.

    Criminals also exploit these cracked copies to establish backdoors on compromised systems, and deploy malware. Notably, investigations into ransomware strains like Ryuk, Trickbot, and Conti have linked them to the use of unlicensed Cobalt Strike, Europol said.

    Paul Foster, director of threat leadership at the National Crime Agency, said, “Although Cobalt Strike is a legitimate piece of software, sadly cybercriminals have exploited its use for nefarious purposes. Illegal versions of it have helped lower the barrier of entry into cybercrime, making it easier for online criminals to unleash damaging ransomware and malware attacks with little or no technical expertise.”

    Foster warned  that such attacks could cost companies millions in terms of losses and recovery.

    Public-Private Partnership: A Winning Formula

    The success of Operation MORPHEUS hinges on the unprecedented cooperation between law enforcement and the private sector. Key industry partners like BAE Systems Digital Intelligence, Trellix, Spamhaus, and The Shadowserver Foundation provided crucial support. Their expertise in threat intelligence, network scanning, and data analysis proved instrumental in identifying malicious activities and pinpointing cybercriminal infrastructure.

    This collaboration is a direct consequence of Europol’s recent regulatory amendments, empowering the agency to work more effectively with private entities. This novel approach grants Europol access to real-time threat intelligence and a broader understanding of cybercriminal tactics. This translates to a more coordinated and comprehensive response, ultimately strengthening the overall cybersecurity posture across Europe.

    Europol’s European Cybercrime Centre (EC3) played a pivotal role throughout the investigation, offering analytical and forensic support while facilitating seamless information exchange between all partners, while the FBI, Australian Federal Police, and other national agencies provided critical support.

    Over the past two and a half years, law enforcement utilized the Malware Information Sharing Platform (MISP) to facilitate real-time threat intelligence sharing with the private sector. Nearly 730 intelligence reports containing almost 1.2 million indicators of compromise (IOCs) were exchanged during the investigation. Additionally, EC3 organized over 40 coordination meetings to ensure smooth collaboration between law enforcement and private partners. Europol even established a virtual command post during the takedown week to coordinate global law enforcement activities.

    The Fight Continues

    While Operation MORPHEUS represents a significant victory, the war against cybercrime is far from over. Law enforcement agencies remain vigilant, prepared to conduct similar disruptive actions as long as criminals continue to exploit vulnerabilities in legitimate security tools.

    Fortra, the developer of Cobalt Strike, has also released a new version with enhanced security measures and is committed to working with law enforcement to remove older, vulnerable versions from circulation.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleAustralia Gives Online Industry Ultimatum to Protect Children from Age-Explicit Harmful Content
    Next Article Windows Recall Remains Insecure, Researcher Says; Google Developing Similar Feature

    Related Posts

    Security

    Nmap 7.96 Launches with Lightning-Fast DNS and 612 Scripts

    May 16, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-4743 – Code-projects Employee Record System SQL Injection Vulnerability

    May 16, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    Hisense unveils a monster 136-inch TV with Micro LED display

    Development

    SELMA: A Speech-Enabled Language Model for Virtual Assistant Interactions

    Machine Learning

    Announcing the Web AI Acceleration Fund

    Development

    Use Claude 3.5 Sonnet With Audio Data & Latest Speech-to-Text Tutorials

    Artificial Intelligence

    Highlights

    Development

    Fabric: An Open-Source Framework for Augmenting Humans Using AI

    August 20, 2024

    The year 2023 witnessed a rapid rise in generative AI, which has led to the…

    Collective #887

    December 6, 2024

    SuperCard X Android Malware Enables Contactless ATM and PoS Fraud via NFC Relay Attacks

    April 21, 2025

    CVE-2024-6648 – AP Page Builder Path Traversal RCE

    May 8, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.