s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1932657 high

📛 Threat Title

Cobalt Strike: Domain that is used for botnet Command&control (C&C) i.gckni.com

Category: Cobalt Strike Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Cobalt Strike (aliases: Agentemis,BEACON,CobaltStrike,cobeacon). Confidence: 75. First seen: 2026-09-25 03:46:53 UTC. Last seen: 2026-09-25 11:47:33 UTC. Reporter: abuse_ch. Tags: CobaltStrike, drb-ra.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain i.gckni.com

IOC database

Type
domain
Value
i.gckni.com
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Domain that is used for botnet Command&control (C&C) attributed to Cobalt Strike

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Cobalt Strike (aliases: Agentemis,BEACON,CobaltStrike,cobeacon). Confidence: 75. First seen: 2026-09-25 03:46:53 UTC. Last seen: 2026-09-25 06:47:38 UTC. Reporter: abuse_ch. Tags: CobaltStrike, drb-ra.

Remediations (10)

  • web:detection.fyi

    Cobalt Strike is a threat emulation platform commonly modified and used by adversaries to conduct network attack and exploitation campaigns. This rule detects a network activity algorithm leveraged by Cobalt Strike implant beacons for command and control.

  • web:feed.craftedsignal.io

    This brief documents the detection of Cobalt Strike command and control activity through identifying specific domain naming conventions used by its implant beacons, indicative of network attack and exploitation campaigns.

  • web:morimori-dev.github.io

    Cobalt Strike is a commercial adversary simulation framework widely used in authorized red team engagements. Understanding its architecture, Beacon payloads, and post-exploitation capabilities is essential for both red teamers and defenders (blue team).

  • web:unit42.paloaltonetworks.com

    Cobalt Strike is a commercial software framework that enables security professionals like red team members to simulate attackers embedding themselves in a network environment. However, threat actors continue to use cracked versions of Cobalt Strike in real-world attacks.

  • web:www.elastic.co

    Cobalt Strike is a penetration testing tool often repurposed by attackers for malicious activities, particularly for establishing command and control (C2) channels. Adversaries exploit its beaconing feature to communicate with compromised systems using common protocols like HTTP or TLS. The detection rule identifies suspicious network patterns, such as specific domain naming conventions ...

  • web:www.elastic.co

    Cobalt Strike is a threat emulation platform commonly modified and used by adversaries to conduct network attack and exploitation campaigns. This rule detects a network activity algorithm leveraged by Cobalt Strike implant beacons for command and control.

  • web:www.manageengine.com

    The Cobalt Strike beacon is a small implant that establishes a command-and-control channel back to a team server operated by the attacker. It supports a wide range of post-exploitation capabilities: process injection, credential dumping, lateral movement, privilege escalation, and file transfer.

  • web:www.securityscientist.net

    How to Detect and Remove Cobalt Strike from Your Environment A practical guide to defending against Cobalt Strike . Covers attack patterns, detection strategies, and prioritised mitigations .

  • web:www.spamhaus.org

    Botnet Threat Update January to June 2026 Between Jan-Jun 2026 botnet C&C servers observed decreased -30% to 14,952. Sliver overtook Cobalt Strike for the #1 spot (+58%). Meanwhile .cn botnet C&C domains surged +771% and India's PDR registrar saw a +901% spike in abused registrations - though REGRU bucked the trend with a -90% reduction. Read the latest report to learn more.

  • web:www.vectra.ai

    Cobalt Strike is a commercial product, and legitimate use is typically licensed through the vendor. Organizations evaluating cost should plan for licensing plus the operational overhead of responsible use (scope control, logging, and detection validation during exercises).

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.