European law enforcement joined forces with the private sector to combat criminals’ abuse of a security tool that they were using to infiltrate the computer systems of the victims.

During a week of police action coordinated from the headquarters of Europol, between 24 and 28 June of this year, older and unlicensed versions of the Cobalt Strike teaming tool were targeted.
Throughout this week, law enforcement agencies marked known IP addresses associated with criminal activities, as well as a series of domain names used by criminal groups, so that online service providers can disable unlicensed versions of the tool. A total of 690 IP addresses were pointed out to online service providers in 27 countries.
Known as Operation MORPHEUS, this investigation was led by the UK’s National Crime Agency and involved police authorities from Australia, Canada, Germany, the Netherlands, Poland, and the United States. Europol organised the international activity and liaised with the private partners. This offensive marks the culmination of a complex investigation launched in 2021.
Cobalt Strike is a popular commercial tool provided by the cybersecurity software company Fortra. It is designed to assist bona fide cybersecurity experts in carrying out attack simulations that identify vulnerabilities in security operations and incident responses.
However, in the wrong hands, unlicensed copies of Cobalt Strike can provide a malicious actor with a wide range of attack capabilities.
Fortra has taken big steps to prevent the abuse of its software and has collaborated with law enforcement during this investigation to protect the legitimate use of its tools. However, in rare circumstances, criminals have stolen previous versions of Cobalt Strike, creating copies to gain unauthorised access to machines through the backdoor and deploy malicious software. These unlicensed versions of the tool have been linked to various malware and ransomware investigations, including those of Ryuk, Trickbot, and Conti.
Cooperation with the private sector was crucial to the success of that European police initiative. Various private industry partners supported the action, including BAE Systems Digital Intelligence, Trellix, Spamhaus, abuse.ch, and The Shadowserver Foundation. These partners deployed enhanced scanning, telemetry, and analytics capabilities to help identify malicious activities and cybercriminals’ use.
This new approach is made possible by the amended Europol Regulation, which has strengthened the Agency’s ability to provide enhanced support to EU Member States, including by collaborating with the private sector. With this new approach, Europol can access real-time threat information and a broader perspective on cybercriminal tactics. This association allows for a more coordinated and holistic response, thereby ultimately enhancing the overall resilience of the digital ecosystem throughout Europe.
Europol’s European Cybercrime Centre (EC3) has been supporting this case since September 2021 by providing analytical and forensic assistance and allowing for the exchange of information among all partners.
Law enforcement used a platform to share malware information, to allow the private sector to share threat information in real time with law enforcement. During the entire investigation, more than 730 pieces of threat intelligence containing nearly 1.2 million compromise indicators were shared.
Additionally, Europol’s EC3 organised more than 40 coordination meetings between law enforcement and private partners. During the action week, Europol established a virtual command post to coordinate global police actions.
_____
Aquest apunt en català / Esta entrada en español / Post en français








