Skip to main content
QUIETLYTIC
Malware

Cobalt Strike

Commercial "adversary simulation" remote access tool, per MITRE ATT&CK, whose interactive post-exploitation capabilities cover the full range of ATT&CK tactics and are widely repurposed by real threat actors.

Threat Level
CRITICAL
Family
Cobalt Strike
Type
OTHER

Overview

Cobalt Strike (MITRE ATT&CK ID S0154) is a commercial, full-featured remote access tool that, per MITRE’s software profile, “bills itself as ‘adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors.’” MITRE documents its interactive post-exploitation capabilities as covering the full range of ATT&CK tactics, executed within a single integrated system. MITRE also notes that Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.

Cobalt Strike is legitimately sold as a penetration-testing and red-team product, but — as MITRE’s extensive documented relationship data shows — it is also one of the most widely repurposed commercial tools among real-world threat actors, from ransomware crews to nation-state groups.

Actors documented using this tool (per MITRE ATT&CK relationship data)

Our ingested data links Cobalt Strike to at least 26 distinct MITRE ATT&CK groups, including Indrik Spider, BlackByte, APT41, Mustang Panda, APT29, Sandworm Team, FIN7, Wizard Spider, and Play — spanning ransomware operators, financially motivated crime groups, and nation-state espionage actors alike.

Notable techniques (per MITRE ATT&CK relationship data)

Techniques MITRE links to Cobalt Strike in our data include Asymmetric Cryptography (T1573.002), BITS Jobs (T1197), Browser Session Hijacking (T1185), Bypass User Account Control (T1548.002), Code Signing (T1553.002), and DNS-based command-and-control (T1071.004).

What we don’t have

MITRE’s ingested data doesn’t include a discovery/first-observed date for software entries — we don’t report one. We have no independent telemetry, detection-rule, or license/customer data beyond MITRE’s STIX bundle, and no way to distinguish legitimate licensed red-team usage from cracked/pirated copies used maliciously in any individual incident.

Frequently Asked Questions

What is Cobalt Strike? A commercial adversary-simulation and post-exploitation tool, per MITRE ATT&CK, legitimately sold for red-team and penetration-testing use but extensively repurposed by real threat actors.

Is Cobalt Strike malware? Not inherently — it’s a legitimate commercial product. MITRE ATT&CK tracks it because pirated or licensed copies are documented as being used by a very wide range of real-world threat actors, from ransomware crews to nation-state groups.

Which threat groups use Cobalt Strike? Per MITRE ATT&CK’s relationship data, at least 26 tracked groups, including APT41, Mustang Panda, APT29, Sandworm Team, and multiple ransomware-affiliated crime groups.


Data sourced from MITRE ATT&CK® (https://attack.mitre.org), software ID S0154, aggregated August 30, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more malware profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Related intelligence


Cross-referenced intelligence


Analyst tools