12271_Blackberry_ContellatingBooklet_FULL_ModifiedLinks.indd
ID: 72491f70-fcc6-45ce-b01c-9ecce663da8a
STIX ID: report--72491f70-fcc6-45ce-b01c-9ecce663da8a
Threat Score
80/100
Uploaded: 2026-08-11
Published Date: 2021-11-15
Last Modified Date: 2021-11-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Finding Beacons in the Dark is a practitioner-focused CTI study of Cobalt Strike: it documents automated collection (Shodan/Rapid7/Censys), staging emulation to retrieve Beacons, static and dynamic decoding of shellcode/PE stagers, config extraction (XOR decoding, YARA rules), and large-scale clustering of artifacts (SSL public keys, JARM, PROCINJ_STUB, rich headers, imphashes). The report presents statistics from ~48k Beacons/6k+ Team Servers, demonstrates operational detection and hunting techniques, provides detection artefacts and YARA rules, and shows OSINT correlation linking infrastructure to many known actors and ransomware campaigns (e.g., APT41, DarkSide, Conti, WizardSpider, TA575), with guidance for XDR, SOC, IR, forensics and ML-based detection efforts.
