evasion (1)

31185686692?profile=RESIZE_400xAnalysts at Sophos' X-Ops group have identified a threat actor operating within a customer environment after an anomalous endpoint generated alerts.  The device, located in a tenant, contained multiple malicious files stored in the directory C:\Users\User\Documents\test. These included Cobalt Strike profiles crafted to mimic legitimate web traffic, a Telegram bot application programming interface mechanism for external command and control communication, Python scripts designed to inject shellcod