BlackBerry Shines Spotlight on Evolving Cobalt Strike Threat in New Book

Nation-state backed APT groups, cyber mercenaries and individual cybercriminals continue to use Cobalt Strike to develop new threats

BlackBerry Limited (NYSE: BB; TSX: BB), today, during the BlackBerry Security Summit, announced a new book: Finding Beacons In the Dark: A Guide to Cyber Threat Intelligence, detailing the evolution and prevalence of one of the most pervasive tools used by threat actors today Cobalt Strike Beacon. The book details ways to protect against malicious Cobalt Strike payloads and outlines how a robust Cyber Threat Intelligence (CTI) lifecycle and extended detection and response (XDR) solution can provide the context needed to stop these threats.

BlackBerry Logo Black (PRNewsfoto/Blackberry Limited)

Initially developed as an adversary simulation tool, Cobalt Strike has evolved into one of the most persistent attack methods used by state-sponsored Advanced Persistent Threat (APT) groups and criminal mercenaries alike. The book highlights the current threats facing organizations, provides a defense framework and uncovers links between cyberattacks previously thought to be disparate.

Cobalt Strike is widely used by red teams and has become heavily abused by cybercriminals due to its malleability and accessibility. The software is feature-rich, allowing for the facilitation of many attack methods and remained a favorite of numerous state-sponsored parties. The software has also played a significant role in the proliferation of ransomware seen over the past 18 months.

For businesses and cybercriminals alike, purchasing existing malware and related tools via underground forums can be significantly cheaper than developing in-house technology, making the use of Cobalt Strike ideal as it presents attribution challenges to law enforcement. This challenge can be further complicated when cyber mercenary groups are working at the behest of larger – potentially nation-state – actors.

"Cobalt Strike presents an almost perfect software for cybercriminals, while highlighting a central conundrum of the security sector – that well-built tools can both aid and increase cybercrime," said Eric Milam , VP Research and Intelligence, BlackBerry. "Cobalt Strike is feature-rich, well supported and actively maintained by its developers. Its payload provides a wealth of features for attackers. This makes it an attractive option for APT groups and cybercrime novices alike."

While the increasing proliferation of Cobalt Strike within the criminal underground presents a reason for concern, so does its continued use by sophisticated APT groups. As recently as October 2021 , APT41 was witnessed using the software in phishing emails targeting Indian citizens, while Dridex operators have used Cobalt Strike heavily to underpin their recent phishing and malspam campaigns .

"The aim of this book is to aid the security community by sharing our knowledge, presenting the steps we've taken to create an automated system to hunt for Cobalt Strike, and most importantly, demonstrating how to derive meaningful threat intelligence from the resulting dataset. This information can then be used to provide insights, trends and intelligence on threat groups and campaigns," said Billy Ho , Executive Vice President of Product Engineering, BlackBerry.

BlackBerry's Finding Beacons In the Dark: A Guide to Cyber Threat Intelligence will be available in November 2021 , and can be preordered at the following website link .

About BlackBerry
BlackBerry (NYSE: BB; TSX: BB) provides intelligent security software and services to enterprises and governments around the world. The company secures more than 500M endpoints including 195M vehicles. Based in Waterloo, Ontario , the company leverages AI and machine learning to deliver innovative solutions in the areas of cybersecurity, safety, and data privacy solutions, and is a leader in the areas of endpoint security, endpoint management, encryption, and embedded systems.  BlackBerry's vision is clear - to secure a connected future you can trust.

BlackBerry. Intelligent Security. Everywhere.

For more information, visit BlackBerry.com and follow @BlackBerry.

Trademarks, including but not limited to BLACKBERRY and EMBLEM Design are the trademarks or registered trademarks of BlackBerry Limited, and the exclusive rights to such trademarks are expressly reserved. All other trademarks are the property of their respective owners. BlackBerry is not responsible for any third-party products or services.

Media Contacts:
BlackBerry Media Relations
+1 (519) 597-7273
mediarelations@BlackBerry.com

Cision View original content to download multimedia: https://www.prnewswire.com/news-releases/blackberry-shines-spotlight-on-evolving-cobalt-strike-threat-in-new-book-301399428.html

SOURCE BlackBerry Limited

News Provided by Canada Newswire via QuoteMedia

The Conversation (0)

Qualcomm's 2023 Corporate Responsibility Report: Resource Management - Waste

Originally published in Qualcomm's 2023 Corporate Responsibility Report

Through our Environmental Program Management Standard, we focus on identifying activities, services and processes that generate waste and strive to reduce the impact of our waste disposal practices on the environment. Our operations generate various types of waste, including general solid waste, hazardous and regulated waste and e-waste, including network infrastructure equipment. Our approach to waste management involves reuse and recycling programs to help us decrease the amount of waste we send to landfills. It also comprises the development of initiatives to reduce our overall waste footprint and the promotion of less toxic, more durable, reusable and recycled materials in our operations. A variety of our business units lead our waste recycling and management programs. They include

News Provided by ACCESSWIRE via QuoteMedia

Keep reading...Show less

Qualcomm Announces Shortlisted Startups for Qualcomm Make in Africa 2024 and Awards 2023 Wireless Reach Social Impact Fund

Qualcomm's Continued Commitment to Empowering Africa's Emerging Technology Ecosystem through Mentorship and Training Initiatives

Qualcomm Incorporated announced the shortlisted startups for Qualcomm Make in Africa 2024, as well as the winner of the 2023 Wireless Reach Social Impact Fund. The Qualcomm Africa Innovation Platform, now in its second year, aims to work with and support the development of Africa's emerging technology ecosystem by providing mentorship, education, and training programs with a focus on 5G, Edge-AIML, Compute, and IoT. This year, Qualcomm received an overwhelming response, with approximately 250 applications from 30 countries

News Provided by ACCESSWIRE via QuoteMedia

Keep reading...Show less

Qualcomm's 2023 Corporate Responsibility Report: Operational Resilience

Maintaining and safeguarding our operations

QualcommOriginally published in Qualcomm's 2023 Corporate Responsibility Report

News Provided by ACCESSWIRE via QuoteMedia

Keep reading...Show less

Qualcomm Schedules Second Quarter Fiscal 2024 Earnings Release and Conference Call

Qualcomm Incorporated (NASDAQ: QCOM) today announced that it will publish the Company's financial results for its second quarter fiscal 2024 on Wednesday, May 1, 2024, after the close of the market on the Company's Investor Relations website, at https://investor.qualcomm.com/financial-information . The earnings release will also be furnished to the Securities and Exchange Commission (SEC) on a Form 8-K, which will be available on the SEC website at http://www.sec.gov .

Qualcomm will host a conference call to discuss its second quarter fiscal 2024 results which will be broadcast live on May 1, 2024, beginning at 1:45 p.m. Pacific Time (PT) at https://investor.qualcomm.com/news-events/events . An audio replay will be available at https://investor.qualcomm.com/news-events/events and via telephone following the live call for 30 days thereafter. To listen to the replay via telephone, U.S. callers may dial (877) 660-6853 and international callers may dial (201) 612-7415. Callers should use reservation number 13745532.

News Provided by Business Wire via QuoteMedia

Keep reading...Show less

Qualcomm's 2023 Corporate Responsibility Report: Future Focused Research and Development

Engineering for Human Progress Starts at Qualcomm.

QualcommOriginally published in Qualcomm's 2023 Corporate Responsibility Report

News Provided by ACCESSWIRE via QuoteMedia

Keep reading...Show less

Qualcomm Announces Quarterly Cash Dividend

Qualcomm Incorporated (NASDAQ: QCOM) today announced a quarterly cash dividend of $0.85 per common share, payable on June 20, 2024, to stockholders of record at the close of business on May 30, 2024.

About Qualcomm

News Provided by Business Wire via QuoteMedia

Keep reading...Show less

Latest Press Releases

Related News

×