Microsoft Threat Intelligence Podcast

Disrupting Cracked Cobalt Strike

Aug 14, 2024
In this enlightening discussion, Richard Boscovich, Assistant General Counsel at Microsoft, Jason Lyons, Principal Investigator at DCU, and Bob Erdman, Associate VP at Fortra, tackle the illegal use of cracked Cobalt Strike in cybercrime. They shed light on innovative DMCA strategies to combat piracy globally and discuss the significant impact of these initiatives on detection engineering. The trio also expresses optimism about extending these methods to other cyber threats, emphasizing the importance of collaboration between the public and private sectors in enhancing cybersecurity.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Cracked Cobalt Strike as Crime Enabler

  • Microsoft identified the widespread use of cracked Cobalt Strike as a key factor in ransomware attacks.
  • This commonality made it a strategic target to disrupt multiple ransomware groups simultaneously.
INSIGHT

Misuse of Legitimate Tool

  • Cobalt Strike is a legitimate red team tool used for adversary emulation.
  • Threat actors misuse cracked versions to perform lateral movement and data exfiltration in attacks.
INSIGHT

Creative Use of DMCA

  • The DMCA, originally for copyright protection, was creatively used to target malware using copyrighted APIs.
  • This legal strategy provided a powerful, enforceable method to prompt takedowns from hosting providers, including through court orders.
Get the Snipd Podcast app to discover more snips from this episode
Get the app