Netskope Threat Labs

BACKDOOR Backdoor.HTTP.BEACON.[CSBundle MSOffice Server]

IPS-SWG

2 SIDs: 140318, 140332

First seen
July 2024
Last seen
July 2024

Detects HTTP responses with the fixed JSON structure of the CSBundle Cobalt Strike Malleable C2 profile, in the variant that disguises the command and control server as a Microsoft Office update service. The identical response body across connections is a strong indicator of an infected client beaconing to its operator.

No cross-references or related blog posts found for this signature.