Skip to content
← Back to newsHackers Exploit GitHub and Social Media for Cobalt Strike Deployments
Security

Hackers Exploit GitHub and Social Media for Cobalt Strike Deployments

By ToTo BugelmanNewcomer0 rep· 7/31/2025

Sophisticated cyberattacks have been targeting organizations, particularly within the Russian IT sector, since the latter half of 2024. Attackers are employing advanced evasion techniques, leveraging popular online platforms like GitHub, Quora, and social media to deliver their malicious payload, ultimately deploying the Cobalt Strike Beacon.

 

A Stealthy Infiltration

The campaign, most active between November 2024 and April 2025, began with highly convincing spear-phishing emails. These emails mimicked communications from major state-owned companies, often in the oil and gas industry, to trick recipients into opening malicious attachments. These attachments were typically RAR archives containing a deceptive structure: a malicious .lnk file, decoy PDF documents, and a hidden directory with executables disguised as PDFs.

 

Example of a spear phishing email

 

Upon execution of the .lnk file, the malware would copy and rename these files within the user's environment, setting the stage for further compromise. A key technique employed was DLL hijacking, exploiting the legitimate BugSplat crash reporting utility (BsSndRpt.exe). The attackers renamed this utility and paired it with a malicious DLL, forcing the utility to load the rogue code instead of its authentic counterpart.

 

Scheme of execution of the shortcut "Requirements.lnk"

 

 

Scheme of work of the nau.exe process

 

Leveraging Legitimate Platforms for Malicious Ends

To further evade detection, the malicious DLL utilized dynamic API resolution and XOR-encrypted hashes, making static analysis difficult. It also hooked Windows API functions, redirecting calls to custom functions within the malicious library. These functions then fetched shellcode from web-based sources, specifically embedding command and control (C2) information and payload URLs within HTML content found in user profiles on platforms like Microsoft Tech Community, Quora, GitHub, and Russian social networks.

 

Malicious profiles on various popular resources

 

This method of hiding malicious data within legitimate user-generated content allowed attackers to create a complex and resilient execution chain. The shellcode, a reflective loader, was designed to inject Cobalt Strike Beacon directly into the process memory, establishing communication with C2 servers. While the identified accounts were purpose-built for the attack, the techniques could easily be adapted to compromise legitimate user posts or comments.

 

Key Takeaways

  • Threat actors are increasingly using sophisticated methods to conceal well-known tools like Cobalt Strike.

  • Legitimate online platforms are being abused to host command and control infrastructure and deliver malicious payloads.

  • DLL hijacking and dynamic API resolution are common evasion techniques.

  • Spear-phishing emails remain a primary initial access vector.

The campaign, while primarily targeting Russian IT companies, also saw activity in China, Japan, Malaysia, and Peru. Organizations are advised to maintain vigilant monitoring, enhance cybersecurity awareness training for staff, and deploy robust security solutions to detect and block such advanced threats. Indicators of compromise include the presence of unsigned BugSplatRc64.dll files or the BugSplat utility appearing with non-standard filenames.

 

Sources

 

Este artículo fue creado con el apoyo de tecnología impulsada por IA, basándose en múltiples fuentes reputadas. El contenido final ha sido revisado y editado minuciosamente por el equipo editorial de BlockzHub para garantizar precisión, claridad y coherencia. Las fuentes originales de los informes se citan siempre que sea apropiado y necesario. Las opiniones expresadas en este artículo no representan necesariamente los puntos de vista o posiciones oficiales de BlockzHub. Este artículo tiene únicamente fines informativos y no debe considerarse asesoramiento financiero o profesional. Invertir implica riesgos, y se recomienda consultar a un asesor financiero calificado antes de tomar decisiones de inversión.

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.

Hackers Exploit GitHub and Social Media for Cobalt Strike Deployments | BlockzHub