Analysts at Sophos' X-Ops group have identified a threat actor operating within a customer environment after an anomalous endpoint generated alerts. The device, located in a tenant, contained multiple malicious files stored in the directory C:\Users\User\Documents\test. These included Cobalt Strike profiles crafted to mimic legitimate web traffic, a Telegram bot application programming interface mechanism for external command and control communication, Python scripts designed to inject shellcod