

Disrupting Cracked Cobalt Strike
Aug 14, 2024
In this enlightening discussion, Richard Boscovich, Assistant General Counsel at Microsoft, Jason Lyons, Principal Investigator at DCU, and Bob Erdman, Associate VP at Fortra, tackle the illegal use of cracked Cobalt Strike in cybercrime. They shed light on innovative DMCA strategies to combat piracy globally and discuss the significant impact of these initiatives on detection engineering. The trio also expresses optimism about extending these methods to other cyber threats, emphasizing the importance of collaboration between the public and private sectors in enhancing cybersecurity.
AI Snips
Chapters
Transcript
Episode notes
Cracked Cobalt Strike as Crime Enabler
- Microsoft identified the widespread use of cracked Cobalt Strike as a key factor in ransomware attacks.
- This commonality made it a strategic target to disrupt multiple ransomware groups simultaneously.
Misuse of Legitimate Tool
- Cobalt Strike is a legitimate red team tool used for adversary emulation.
- Threat actors misuse cracked versions to perform lateral movement and data exfiltration in attacks.
Creative Use of DMCA
- The DMCA, originally for copyright protection, was creatively used to target malware using copyrighted APIs.
- This legal strategy provided a powerful, enforceable method to prompt takedowns from hosting providers, including through court orders.