FOLLOW US

Wed

June 24, 2026

America July 3, 2021 4 mins read

Cobalt Strike used in ransomware attack prevented by Cybersecurity

America ı By Jackie Allen

0 Comments

Ransomware-Cartoon_compressed

Cybersecurity researchers at Sophos were brought in to investigate after Cobalt Strike was detected on its network.

It was reported in ZDNet in May that Cobalt Strike is being weaponized in malware campaigns. The cybersecurity tool is now being used by threat actors, as well.

In May the Ransomware Task Force issued a report with recommendations on the increasing number of ransomware attacks in the U.S.

Cobalt strike used in attempted malware infection 

The company that experienced the threat chooses to remain anonymous. But they have allowed the release of details of the investigation. They hope that other businesses and organizations can learn how to avoid similar attacks.

Cobalt Strike is primarily used by cybercriminals because it partially runs in-memory, which makes it hard to detect on a network. And that was the case here. It looked like legitimate access software was being remotely installed on 130 endpoints of the business network. 

The ransomware gang was responsible for the remote desktop software. This was the foundation for the ransomware attack. Their next step would have been to encrypt the entire network with REvil ransomware.

REvil ransomware that was used in another incident investigated by Sophos. It was successfully deployed against JBS who paid $11 million for the decryption key.

The ransomware gang managed to encrypt data on some of the unprotected devices. They also deleted online backups when they noticed the investigators were working on the case. 

A ransom note was left by REvil on one of the few encrypted devices. The cybercriminals wanted $2.5 million in bitcoin for a decryption key.  

Naturally, in this case, no ransom was paid. The company had already discovered the planted software. And the cybercriminals were stopped in their tracks when cybersecurity experts were called in. 

Issues with Remote Access

The fact remains that attackers managed to gain enough control of the network to install software on over 100 machines. The company did discover the attack just in time. But it was close.

Paul Jacobs, the incident response lead at Sophos explains why the targeted company didn't notice what was happening on their network sooner.

"As a result of the pandemic, it's not unusual to find remote access applications installed on employee devices," Jacobs explains.

"When we saw Screen Connect on 130 endpoints, we assumed it was there intentionally, to support people working from home. It turned out the company knew nothing about it – the attackers had installed the software to ensure they could maintain access to the network and compromised devices."

12

Previous Article

Democrats Not Confident in Possible Harris 2024 Presidential Run

Read More
Jackie Allen
3192 Posts

Jackie Allen

Jackie is a freelance journalist and technology geek. She worked as a telecom project director for AT&T and BellSouth. Before joining the USA Herald she has written books, articles, blogs and whitepapers. Her clients include Samsung and other technology companies.

Discussion

No comments yet. Be the first to join the discussion!

Don’t Miss It
High Profile Court Cases June 23, 2026
€100,000 Reward Offered in Hunt for Barcelona Watch Thief
By – Tyler Brooks
High Profile Court Cases June 23, 2026
The Sleight-of-Hand City
By – Tyler Brooks
America June 23, 2026
Was Marilyn Monroe Murdered?
By – Jackie Allen
Arizona January 11, 2025
Kelly Warner Law Firm Blames USA…

In what appears as a desperate attempt to defend multiple…

By – USA Herald
Arizona January 4, 2025
Aaron Kelly Law Firm Resorts To…

Attorney Aaron Kelly and his law partner Daniel Warner are…

By – Jeff Watterson
Arizona December 12, 2024
Arizona Bar Opens Investigation on Attorney…

USA Herald recently reported on a developing story involving Attorneys…

By – Paul O'Neal
America June 23, 2026
‘I Have Met Non-Human Intelligence in…

By Samuel López | USA Herald They walk among us.…

By – Samuel Lopez
America June 23, 2026
Biden Cognitive Issues: Court Fight Over…

Questions about Biden cognitive issues surround the former President. This…

By – Jackie Allen
Entertainment June 23, 2026
Kourtney Kardashian Celebrates Travis Barker on…

Kourtney Kardashian had plenty of love to share this Father’s…

By – Tyler Brooks
Entertainment June 23, 2026
Jay-Z and Roc Nation Win Major…

The legal war between rap mogul Jay-Z and Houston-based attorney…

By – Tyler Brooks
High Profile Court Cases June 23, 2026
The Etan Patz Case Is Finally…

The Etan Patz Case Is Finally Over: Supreme Court Upholds…

By – Tyler Brooks
America June 23, 2026
Tesla Self-Driving Car Crashes Into Texas…

Federal safety regulators in the United States have launched a…

By – Tyler Brooks
America June 23, 2026
Tesla Self-Driving Car Crashes Into Texas…

Federal safety regulators in the United States have launched a…

By – Tyler Brooks
America June 23, 2026
NASA Astronaut Heading to Space Station…

For decades, the question of whether life exists beyond Earth…

By – Tyler Brooks
America June 22, 2026
Chevron Locks in 20-Year Deal to…

In a landmark partnership that underscores the growing energy demands…

By – Rihem Akkouche
America June 22, 2026
World Cup History Made as Lionel…

World Cup history was made Monday afternoon in Arlington, Texas,…

By – Jackie Allen
America June 22, 2026
Lucid Motors Slashes 18% of U.S.…

Lucid Group, the luxury electric vehicle maker once seen as…

By – Rihem Akkouche
America June 22, 2026
Federal Judge Slams Trump DOJ for…

A federal judge has delivered a blistering rebuke to the…

By – Rihem Akkouche
America June 22, 2026
Final Wish: Oliver Tree’s Family Honors…

Final Wish is how the family of singer Oliver Tree…

By – Jackie Allen
America June 21, 2026
Reflecting Pool Incident Leads to Arrest…

The Reflecting Pool at the Lincoln Memorial has become the…

By – Jackie Allen
America June 21, 2026
Nuclear Talks Begin in Switzerland as…

Nuclear Talks between the United States and Iran officially began…

By – Jackie Allen
America June 20, 2026
Pizza Hut to Be Sold in…

Pizza Hut is entering a new chapter after parent company…

By – Jackie Allen
America June 19, 2026
Jane Street Emerges from the Shadows…

Jane Street is one of the most secretive and profitable…

By – Jackie Allen
America June 19, 2026
Peace Agreement Between US and Iran…

A proposed Peace Agreement framework between the United States and…

By – Jackie Allen
America June 19, 2026
Peace Agreement Between US and Iran…

A proposed Peace Agreement framework between the United States and…

By – Jackie Allen
America June 18, 2026
Internet’s First Serial Killer Used Early…

The story of Serial Killer John Edward Robinson remains one…

By – Jackie Allen
America June 18, 2026
The 9-Second Disaster: The Edge of…

The tech industry is learning that AI autonomy can be…

By – Jackie Allen
America June 17, 2026
Southern Poverty Law Center Indictments Linked…

The Southern Poverty Law Center (SPLC), one of the nation’s…

By – Jackie Allen
America June 16, 2026
Anna Kepner Killing: Federal Judge Orders…

The legal proceedings surrounding the cruise ship murder of Anna…

By – Jackie Allen
America June 16, 2026
Russia Shadow Fleet Captain Faces UK…

The captain of a Russian Shadow Fleet tanker intercepted by…

By – Jackie Allen
Entertainment June 22, 2026
GTA 6 Music File Discovered in…

With GTA 6 pre-orders officially opening on Thursday, June 25,…

By – Tyler Brooks
Business June 22, 2026
Toy Story 5 Shatters Box Office…

When the lights dimmed and the familiar Pixar lamp bounced…

By – Tyler Brooks
Entertainment June 22, 2026
BTS Comeback Tour Ticket Chaos: Fans…

The long awaited return of global K-pop sensation BTS has…

By – Tyler Brooks
America June 20, 2026
Ubisoft Co-Founder Claude Guillemot Dies at…

Claude Guillemot, the co-founder of one of the world’s largest…

By – Rihem Akkouche
America June 19, 2026
Anne Hathaway, 43, Stuns Fans with…

In a beautiful and unexpected moment that has sent the…

By – Rihem Akkouche
America June 19, 2026
Hollywood Icon’s Daughter and Husband Found…

In a heartbreaking and mysterious tragedy, Judith Sheldon — daughter…

By – Rihem Akkouche
Health June 23, 2026
Your Blood Pressure Reading May Be…

Millions of people living with high blood pressure believe that…

By – Tyler Brooks
America June 6, 2026
Nichelle Nichols’ Final Mission Ends in…

By Samuel López | USA Herald The woman who helped…

By – Samuel Lopez
America June 5, 2026
Cannabis Giants Hit with Sweeping Class…

A major class action filed May 4, 2026, accuses five…

By – Samuel Lopez
Health June 1, 2026
New Pill Doubles Survival for Pancreatic…

Pancreatic cancer pill doubles life to 13 months By Tyler…

By – Tyler Brooks
California News May 31, 2026
FDA warns public as cookie firm…

FDA warns public as cookie firm rejects urgent recall request…

By – Tyler Brooks
Health May 31, 2026
Trump orders CDC to slash childhood…

Trump orders CDC to slash childhood vaccines from 17 to…

By – Tyler Brooks
America June 22, 2026
Lionel Messi, at 39, Shatters All-Time…

Lionel Messi has done it again. The Argentine superstar etched…

By – Rihem Akkouche
Pennsylvania June 22, 2026
Will a Massive Storm Derail the…

The 2026 FIFA World Cup is already delivering unforgettable moments…

By – Tyler Brooks
Sports June 18, 2026
Extraterrestrial Kickoff? Viral Psychic Warns of…

Football fans around the globe are currently deep in the…

By – Tyler Brooks
Business June 16, 2026
Dana White Declares The Historic UFC…

WASHINGTON D.C. — It was 3:00 a.m. on Monday, and…

By – Tyler Brooks
Sports June 15, 2026
Pulisic Is Not Training. What Happens…

Mauricio Pochettino pulled Christian Pulisic at halftime of the USMNT’s…

By – Nicolas Carreno
America June 14, 2026
New York Chaos Erupts After Knicks…

New York Chaos unfolded across the city after the New…

By – Jackie Allen

No posts found.

No posts found.

Signup for the USA Herald
exclusive Newsletter