BlackBerry Shines Spotlight on Evolving Cobalt Strike Threat in New Book

Nation-state backed APT groups, cyber mercenaries and individual cybercriminals continue to use Cobalt Strike to develop new threats

BlackBerry Limited (NYSE: BB; TSX: BB), today, during the BlackBerry Security Summit, announced a new book: Finding Beacons In the Dark: A Guide to Cyber Threat Intelligence, detailing the evolution and prevalence of one of the most pervasive tools used by threat actors today Cobalt Strike Beacon. The book details ways to protect against malicious Cobalt Strike payloads and outlines how a robust Cyber Threat Intelligence (CTI) lifecycle and extended detection and response (XDR) solution can provide the context needed to stop these threats.

BlackBerry Logo Black (PRNewsfoto/Blackberry Limited)

Initially developed as an adversary simulation tool, Cobalt Strike has evolved into one of the most persistent attack methods used by state-sponsored Advanced Persistent Threat (APT) groups and criminal mercenaries alike. The book highlights the current threats facing organizations, provides a defense framework and uncovers links between cyberattacks previously thought to be disparate.

Cobalt Strike is widely used by red teams and has become heavily abused by cybercriminals due to its malleability and accessibility. The software is feature-rich, allowing for the facilitation of many attack methods and remained a favorite of numerous state-sponsored parties. The software has also played a significant role in the proliferation of ransomware seen over the past 18 months.

For businesses and cybercriminals alike, purchasing existing malware and related tools via underground forums can be significantly cheaper than developing in-house technology, making the use of Cobalt Strike ideal as it presents attribution challenges to law enforcement. This challenge can be further complicated when cyber mercenary groups are working at the behest of larger – potentially nation-state – actors.

"Cobalt Strike presents an almost perfect software for cybercriminals, while highlighting a central conundrum of the security sector – that well-built tools can both aid and increase cybercrime," said Eric Milam , VP Research and Intelligence, BlackBerry. "Cobalt Strike is feature-rich, well supported and actively maintained by its developers. Its payload provides a wealth of features for attackers. This makes it an attractive option for APT groups and cybercrime novices alike."

While the increasing proliferation of Cobalt Strike within the criminal underground presents a reason for concern, so does its continued use by sophisticated APT groups. As recently as October 2021 , APT41 was witnessed using the software in phishing emails targeting Indian citizens, while Dridex operators have used Cobalt Strike heavily to underpin their recent phishing and malspam campaigns .

"The aim of this book is to aid the security community by sharing our knowledge, presenting the steps we've taken to create an automated system to hunt for Cobalt Strike, and most importantly, demonstrating how to derive meaningful threat intelligence from the resulting dataset. This information can then be used to provide insights, trends and intelligence on threat groups and campaigns," said Billy Ho , Executive Vice President of Product Engineering, BlackBerry.

BlackBerry's Finding Beacons In the Dark: A Guide to Cyber Threat Intelligence will be available in November 2021 , and can be preordered at the following website link .

About BlackBerry
BlackBerry (NYSE: BB; TSX: BB) provides intelligent security software and services to enterprises and governments around the world. The company secures more than 500M endpoints including 195M vehicles. Based in Waterloo, Ontario , the company leverages AI and machine learning to deliver innovative solutions in the areas of cybersecurity, safety, and data privacy solutions, and is a leader in the areas of endpoint security, endpoint management, encryption, and embedded systems.  BlackBerry's vision is clear - to secure a connected future you can trust.

BlackBerry. Intelligent Security. Everywhere.

For more information, visit BlackBerry.com and follow @BlackBerry.

Trademarks, including but not limited to BLACKBERRY and EMBLEM Design are the trademarks or registered trademarks of BlackBerry Limited, and the exclusive rights to such trademarks are expressly reserved. All other trademarks are the property of their respective owners. BlackBerry is not responsible for any third-party products or services.

Media Contacts:
BlackBerry Media Relations
+1 (519) 597-7273
mediarelations@BlackBerry.com

Cision View original content to download multimedia: https://www.prnewswire.com/news-releases/blackberry-shines-spotlight-on-evolving-cobalt-strike-threat-in-new-book-301399428.html

SOURCE BlackBerry Limited

News Provided by Canada Newswire via QuoteMedia

The Conversation (0)

Our Approach to Clean and Renewable Energy

At Meta, we work to design, build and operate some of the most innovative and sustainable data centers in the world. They provide the technology that billions of people use every day to connect and build community. Ensuring these world-class data centers are supported by clean and renewable energy is foundational to our approach. We recognize that adding new energy to the grid is important, not only because of our scale and scope as a company, but because we want to play a positive role in the communities in which we operate

Since 2020, we have matched 100% of our annual electricity use with new renewable energy and have a long history of partnering with utilities and renewable developers to bring new wind and solar energy projects to grids where we operate. As a voluntary buyer of renewable energy, we prioritize supporting high quality, innovative clean and renewable energy projects around the globe, which is key to maintaining net zero emissions for our operations.

News Provided by ACCESSWIRE via QuoteMedia

Keep reading...Show less

Growing Our Commitment to Carbon Removal With the U.S. Department of Energy

Meta

Meta is pledging to contract at least $35 million for carbon removal projects in the coming year as part of our goal to achieve net zero emissions across our value chain in 2030. This is a direct response to the Carbon Dioxide Removal Purchasing Challenge presented by the U.S. Department of Energy (DOE), which calls for companies to help catalyze carbon removal at gigaton scales in the coming decades. Our pledge matches DOE's own commitment to advance technologies that remove carbon dioxide directly from the atmosphere.

News Provided by ACCESSWIRE via QuoteMedia

Keep reading...Show less

How Our Llama Grant Recipients Are Tackling Global Issues

MetaTakeaways

  • Today, we're excited to announce the recipients of the 2023 Llama Impact Grants, who will be awarded $500,000 each to support their use of AI to address pressing social issues.

News Provided by ACCESSWIRE via QuoteMedia

Keep reading...Show less

Meta at UNGA 2024

Meta

Takeaways

News Provided by ACCESSWIRE via QuoteMedia

Keep reading...Show less

Apple extends its privacy leadership with new updates across its platforms

Private Cloud Compute sets a new standard for privacy in artificial intelligence

Apple® today announced new updates across its platforms that help empower users and keep them in control of their data. Private Cloud Compute extends the industry-leading protections of iPhone® to the cloud, so that users don't have to choose between powerful intelligence grounded in their personal context and strong privacy protections. Apple also raised the bar for privacy with new features, such as locked and hidden apps, aimed at helping users protect sensitive areas of their phones. Apple introduced additional features designed with privacy and security in mind, including categorization in Mail, Messages via satellite, and presenter preview.

News Provided by Business Wire via QuoteMedia

Keep reading...Show less

Apple empowers developers and fuels innovation with new tools and resources

Enhancements to Xcode and Swift, combined with new APIs, offer developers expanded capabilities for creating high-quality apps

Apple® today unveiled a suite of innovative new tools and resources designed to enable developers worldwide to create more powerful and efficient apps across all Apple platforms. With Xcode® 16, developers can save time in their development process and get more done thanks to features like Swift® Assist and predictive code completion. New and expanded APIs give developers the tools to advance their apps and introduce exciting features.

News Provided by Business Wire via QuoteMedia

Keep reading...Show less

Latest Press Releases

Related News

×