H-ISAC TLP White Indicator Sharing: Threat Actor Selling Cobalt Strike Cryptor, Claims Will Bypass Most Security Sensors

Recently, DeepSeas Darkweb team discovered a post from a credible XSS crime forum account selling access to a cryptor for a cracked version of Cobalt Strike 4.7.2 and claims it will bypass several popular security sensors. 

The threat actor is offering subscription access to the cryptor service at tiered prices depending on which security control the buyer wishes to bypass.

View the detailed report below. 

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272