Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

Move over, Cobalt Strike. Splinter’s the new post-exploit menace in town

post, september 23, 2024februari 24, 2025

Attackers are using Splinter, a new post-exploitation tool, to wreak havoc in victims’ IT environments after initial infiltration, utilizing capabilities such as executing Windows commands, stealing files, collecting cloud service account info, and downloading additional malware onto victims’ systems. Then the malicious code self-deletes, according to Palo Alto Networks’ Unit 42 threat hunters, which spotted the new penetration testing tool hiding in several of its customers’ systems.

[…]

Splinter also uses a JSON format for its configuration data that contains the implant ID and targeted endpoint ID, along with the command-and-control (C2) server details. “Upon execution, the sample parses the configuration data and it uses the network information to connect to the C2 server using HTTPS with the login credentials,” Reichel noted.

Move over, Cobalt Strike, there’s a new post-exploit tool • The Register: Move over, Cobalt Strike. Splinter’s the new post-exploit menace in town
cybersecurity 2024Command and ControlCredential Access

Bericht navigatie

Previous post
Next post

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes