VORANT. Threat Intelligence Sign in Get the full feed

CrossC2 loader links Linux Cobalt Strike attacks to Black Basta

high threat

JPCERT/CC observed attackers using CrossC2 to run Cobalt Strike Beacons on Linux/macOS alongside a custom loader chain tied by infrastructure overlap to Black Basta.

Between September and December 2024, JPCERT/CC investigated intrusions using CrossC2, an unofficial cross-platform extension that lets attackers generate Cobalt Strike Beacons for Linux and macOS in addition to Windows. The attacker combined CrossC2 with standard Cobalt Strike, PsExec, Plink, and GetNPUsers (AS-REP Roasting) in apparent attempts to compromise Active Directory environments, while also deploying ELF variants of SystemBC on Linux hosts — systems that frequently lack EDR coverage and thus serve as durable footholds.

On the Windows side, JPCERT/CC identified a custom loader dubbed ReadNimeLoader, written in Nim and sideloaded via a legitimate java.exe (jli.dll) launched from an attacker-created Scheduled Task. ReadNimeLoader decrypts a companion readme.txt using AES-256-ECB with a key partially embedded inside its anti-debugging routines, then hands execution to OdinLdr, an open-source shellcode loader that decodes and runs the Cobalt Strike Beacon in memory, periodically re-encrypting it with a random XOR key to evade memory scanners. Both CrossC2 and ReadNimeLoader employ heavy junk-code insertion and string XOR-encoding as anti-analysis measures. Files were staged under C:\$recycle.bin\, and some samples carried a spoofed Battle.net Launcher PDB path.

JPCERT/CC assesses a potential link to Black Basta based on overlapping infrastructure (a C2 domain matching one in Rapid7's Black Basta reporting), shared filenames (jli.dll, readme.txt), consistent use of SystemBC, and AS-REP Roasting during AD attacks. VirusTotal submissions suggest the campaign was not limited to Japan. JPCERT/CC released a public CrossC2 Beacon configuration parser to aid detection and analysis.

Mentioned in this report

Threat actors Black Basta
Malware Cobalt StrikeCrossC2GetNPUsersOdinLdrPlinkPsExecReadNimeLoaderSystemBC

Source reporting: https://blogs.jpcert.or.jp/en/2025/08/crossc2.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free