Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • NCA leads op to degrade illegal versions of Cobalt Strike

Security

NCA leads op to degrade illegal versions of Cobalt Strike

The National Crime Agency (NCA) has coordinated international action against illicit software which has been used by cybercriminals for over a decade to infiltrate victims’ IT systems and conduct attacks.

Image courtesy NCA

Unlicensed versions of Cobalt Strike, a penetration testing tool used to check for vulnerabilities in a company’s network and help improve cyber security, were targeted during a week of action last week.

Since the mid 2010s, pirated and unlicensed versions of the software downloaded by criminals from illegal marketplaces and the dark web have gained a reputation as the ‘go-to’ network intrusion tool for those seeking to build a cyber attack, allowing them to deploy ransomware at speed and at scale.

Advertisement
ODU RT

Due to the range of tools, free training guides and videos that come with legal versions of the software, those adopting it for criminal use require low levels of sophistication and money.

This disruption activity represents more than two-and-a-half years of NCA-led international law enforcement and private industry collaboration to identify, monitor and denigrate its use.

Action was taken against 690 individual instances of malicious Cobalt Strike software located at 129 internet service providers in 27 countries. By the end of the week, 593 of these addresses had been taken down.

This was achieved through the NCA and law enforcement partners taking down servers and amplified by ‘abuse notifications’ from law enforcement and private industry partners, highlighting to service providers that they may be hosting malware.

Illicit versions of Cobalt Strike have been identified as being used in some of the biggest cyber incidents in recent times. Its use has also been identified in multiple malware and ransomware investigations including those into RYUK, Trickbot and Conti attacks.

The operation was jointly conducted with Europol, who assisted with international coordination, the FBI, Australian Federal Police, Royal Canadian Mounted Police, German Federal Criminal Police Office (Bundeskriminalamt), Netherlands National Police (Politie) and the Polish Central Cybercrime Bureau.

A number of private industry partners, including BAE Systems Digital Intelligence, Trellix, Shadowserver, Spamhaus and Abuse CH also supported law enforcement in identifying malicious instances and use of Cobalt Strike by cybercriminals.

Using a platform known as the Malware Information Sharing Platform, private sector organisations shared real time threat intelligence with law enforcement. More than 730 pieces of threat intelligence containing almost 1.2 million indicators of compromise were shared.

Advertisement
ODU RT

Cyber criminals deploy unlicensed versions of Cobalt Strike via spear phishing or spam emails, which attempt to get a target to click on links or open malicious attachments. When a victim opens the link or document, a Cobalt Strike ‘Beacon’ is installed giving the threat actor remote access, enabling them to profile the infected host, download malware or ransomware and steal data to then extort the victim.

Paul Foster, Director of Threat Leadership at the National Crime Agency, said: “Although Cobalt Strike is a legitimate piece of software, sadly cybercriminals have exploited its use for nefarious purposes.

“Illegal versions of it have helped lower the barrier of entry into cybercrime, making it easier for online criminals to unleash damaging ransomware and malware attacks with little or no technical expertise.

“Such attacks can cost companies millions in terms of losses and recovery.

“International disruptions like these are the most effective way to degrade the most harmful cyber criminals, by removing the tools and services which underpin their operations.

“I would urge any businesses that may have been a victim of cyber crime to come forward and report such incidents to law enforcement.”

Cobalt Strike owners Fortra will continue to work with law enforcement to identify and remove older and malicious versions of the programme from the internet.

Advertisement
FIA2026 animated banner
Smiths Detection’s SDX 10080 SCT achieves ECAC EDS Standard 3.1

Aerospace Security

Smiths Detection’s SDX 10080 SCT achieves ECAC EDS Standard 3.1

28 April 2026

Smiths Detection today announced that its SDX 10080 SCT has received ECAC EDS Standard 3.1 approval for hold baggage and air cargo screening - one of the most rigorous aviation security certifications, recognised across 44 ECAC member states spanning Europe and beyond.

Glasgow Airport hosts emergency training exercise

Aerospace Security

Glasgow Airport hosts emergency training exercise

28 April 2026

Glasgow Airport successfully hosted a multiagency emergency training exercise on Thursday 23rd April, carried out between 7.30pm and 11.30pm, as part of its ongoing commitment to safety, resilience and emergency preparedness.

Cyber agencies share advice on countering China-linked covert networks

Security

Cyber agencies share advice on countering China-linked covert networks

27 April 2026

GCHQ’s National Cyber Security Centre (NCSC) with UK industry and 15 international partners have issued advice on best protections against methods used by China-linked threat actors.

UKEF partners with Finance for Forces to support veteran-led exporters

Aerospace Defence Security Space

UKEF partners with Finance for Forces to support veteran-led exporters

24 April 2026

UK Export Finance (UKEF) – the government’s export credit agency – has announced a new partnership with Finance for Forces to help more veteran-led businesses access the finance they need to grow internationally.

Advertisement
ODU RT
Police Scotland’s national roll out of body worn video to frontline officers concluded

Security

Police Scotland’s national roll out of body worn video to frontline officers concluded

24 April 2026

Police Scotland’s national roll out of body worn video to frontline officers concluded this week, with officers on duty with the cameras in Renfrewshire & Inverclyde (K Division) and Argyll and West Dunbartonshire (L Division)

Air ambulance pilots and CAA issue warning to drone flyers on World Pilot Day

Aerospace Security

Air ambulance pilots and CAA issue warning to drone flyers on World Pilot Day

24 April 2026

On World Pilot Day (Sunday 26th April) air ambulance pilots are teaming up with the UK Civil Aviation Authority (CAA) to urge drone users to fly responsibly after emergency helicopter flights were disrupted by drones during lifesaving missions in 2025.

Advertisement
ODU RT
Advertisement
FIA2026 animated banner