Looks like it’s going to be an eventful year for the @c2_matrix! I’m expecting smaller updates from @_CobaltStrike 💤, some fresh tools from @MDSecLabs once they get over their fear of cashing in 😉, and maybe even a new player ready to raise hell 🐈⬛
Wrote a Beacon Object File (BOF) version of PrintSpoofer for Cobalt Strike. It enables privilege escalation from NetworkService to SYSTEM. Based on work by @tiraniddo and @itm4n.
Repo is here:
github.com/slimeonsecurity/P…
[4/7] 🛡️ Advanced evasion: Microsoft Graph API for C2 comms. Process hollowing injecting into svchost.exe. Steganography in Discord image metadata. Scheduled tasks masked as Windows updates. Custom proxies hiding C2 traffic.
Cobalt Strike 4.11 is out now! This release introduces a novel Sleepmask, a novel process injection technique, a new prepend reflective loader with new evasive options, asynchronous BOFs, DNS over HTTPs and more!
cobaltstrike.com/blog/cobalt…