logo

GENERAL__2020__Multi-stage_APT_attack_drops_Cobalt_Strike_using_Malleable_C2_feature_-_Malwarebytes_Labs_Malwarebytes_Labs.pdf

ID: db619e1a-c215-4396-8e07-47da7b6cadd4

STIX ID: report--db619e1a-c215-4396-8e07-47da7b6cadd4

Threat Score

78/100

Uploaded: 2026-08-19

Published Date: 2020-06-18

Last Modified Date: 2020-06-18

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report documents a multi-stage APT-like campaign that starts with a malicious Word resume exploiting template injection to drop a .NET loader, establishes persistence, then uses a Malleable C2 profile of Cobalt Strike to download and execute a second payload and maintain beaconing to a C2 domain, providing IoCs and attribution context for Mustang Panda/APT41-style activity.