Move over, Cobalt Strike. Splinter’s the new post-exploit menace in town post, september 23, 2024februari 24, 2025 Attackers are using Splinter, a new post-exploitation tool, to wreak havoc in victims’ IT environments after initial infiltration, utilizing capabilities such as executing Windows commands, stealing files, collecting cloud service account info, and downloading additional malware onto victims’ systems. Then the malicious code self-deletes, according to Palo Alto Networks’ Unit 42 threat hunters, which spotted the new penetration testing tool hiding in several of its customers’ systems. […] Splinter also uses a JSON format for its configuration data that contains the implant ID and targeted endpoint ID, along with the command-and-control (C2) server details. “Upon execution, the sample parses the configuration data and it uses the network information to connect to the C2 server using HTTPS with the login credentials,” Reichel noted. Move over, Cobalt Strike, there’s a new post-exploit tool • The Register: Move over, Cobalt Strike. Splinter’s the new post-exploit menace in town cybersecurity 2024Command and ControlCredential Access