Cobalt Strike Beacon Delivered via GitHub and Social Media: A Sophisticated Attack Campaign
In a recent series of cyberattacks, Russian IT companies and entities in other countries were targeted by sophisticated threat actors. The attackers employed a range of malicious techniques to evade detection, including delivering information about their payload via social media and popular user-generated content sites. The campaign was most active during November and December 2024, but continued until April 2025, with a two-month silence after which our security solutions began detecting attacks again.
Key Takeaways:
- The attackers used spear phishing emails with malicious attachments to initiate the attack, disguising the emails as legitimate communications from major state-owned companies.
- The attachments were RAR archives with a specific structure, containing decoy files and executables.
- The attackers employed DLL Hijacking (T1574.001) to deploy their malicious payload, exploiting the legitimate Crash reporting Send Utility (BsSndRpt.exe) and renaming it to nau.exe.
- The malicious library, BugSplatRc64.dll, used Dynamic API Resolution (T1027.007) to obscure API functions, resolving them dynamically only during execution.
- The attackers used legitimate online platforms, such as GitHub, Microsoft Learn Challenge, Quora, and Russian social media platforms, to host C2 addresses and store malicious information.
- The malicious agent uses a reflective loader to inject Cobalt Strike Beacon into the process memory and then hands over control to it (T1620).
- The campaign targeted Russian IT companies, but also had victims in China, Japan, Malaysia, and Peru, with most targets being large and medium-sized businesses.
Statistics:
- The attacks were most active during November and December 2024, but continued until April 2025.
- The attackers used 14 different URLs to store malicious information, including GitHub and Microsoft Learn Challenge.
- The malware used a reflective loader to infect the target system.
- The campaign targeted 87 unique IP addresses worldwide.
- The attackers used a custom hashing algorithm to encrypt the shellcode, which was then decrypted using XOR.
Sources:
- [1] Securelist -- Kaspersky. (2024). Cobalt Strike Beacon delivered via GitHub and social media. Retrieved from
- [1] MIL OSI Global Banks (http://milnz.co.nz/mil-osi-aggregation/). (2025). MIL OSI Global Banks. Retrieved from