Cobalt Strike Beacon Delivered via GitHub and Social Media: A Sophisticated Attack Campaign

In a recent series of cyberattacks, Russian IT companies and entities in other countries were targeted by sophisticated threat actors. The attackers employed a range of malicious techniques to evade detection, including delivering information about their payload via social media and popular user-generated content sites. The campaign was most active during November and December 2024, but continued until April 2025, with a two-month silence after which our security solutions began detecting attacks again.

Key Takeaways:

  • The attackers used spear phishing emails with malicious attachments to initiate the attack, disguising the emails as legitimate communications from major state-owned companies.
  • The attachments were RAR archives with a specific structure, containing decoy files and executables.
  • The attackers employed DLL Hijacking (T1574.001) to deploy their malicious payload, exploiting the legitimate Crash reporting Send Utility (BsSndRpt.exe) and renaming it to nau.exe.
  • The malicious library, BugSplatRc64.dll, used Dynamic API Resolution (T1027.007) to obscure API functions, resolving them dynamically only during execution.
  • The attackers used legitimate online platforms, such as GitHub, Microsoft Learn Challenge, Quora, and Russian social media platforms, to host C2 addresses and store malicious information.
  • The malicious agent uses a reflective loader to inject Cobalt Strike Beacon into the process memory and then hands over control to it (T1620).
  • The campaign targeted Russian IT companies, but also had victims in China, Japan, Malaysia, and Peru, with most targets being large and medium-sized businesses.

Statistics:

  • The attacks were most active during November and December 2024, but continued until April 2025.
  • The attackers used 14 different URLs to store malicious information, including GitHub and Microsoft Learn Challenge.
  • The malware used a reflective loader to infect the target system.
  • The campaign targeted 87 unique IP addresses worldwide.
  • The attackers used a custom hashing algorithm to encrypt the shellcode, which was then decrypted using XOR.

Sources:

  • [1] Securelist -- Kaspersky. (2024). Cobalt Strike Beacon delivered via GitHub and social media. Retrieved from
  • [1] MIL OSI Global Banks (http://milnz.co.nz/mil-osi-aggregation/). (2025). MIL OSI Global Banks. Retrieved from