Uploaded August 2026 | Updated September 2026, 2 hours ago
Naoki Takayama (Internet Initiative Japan Inc., JP)
Cobalt Strike remains one of the most widely abused post‑exploitation frameworks, favored by both cybercrime groups and state‑sponsored APT actors. In recent years, defenders have significantly improved their tooling and techniques for detecting and analyzing the Cobalt Strike Beacon. As a response to this, some threat actors have shifted toward reimplementation of the Cobalt Strike Beacon written in modern programming languages such as Rust and Go. These new variants offer improved stealth, flexible customization, and inherent evasive characteristics originating from their language ecosystems.
This talk will present an in‑depth analysis of these emerging variants, exploring their architecture, behaviors, and notable samples observed in the wild. Additionally, we will offer practical strategies for blue teams, including configuration‑extraction methods and YARA detection rules designed to identify these new threats.
---
Naoki Takayama is a security researcher at Internet Initiative Japan, Inc. As a member of IIJ-SECT, the private CSIRT of his company, he is engaged in threat research and incident response. His research focuses on malware and tactics used in targeted attacks. He has spoken at BSides Tokyo and VB in the past.
Naoki Takayama (Internet Initiative Japan Inc., JP)
Cobalt Strike remains one of the most widely abused post‑exploitation frameworks, favored by both cybercrime groups and state‑sponsored APT actors. In recent years, defenders have significantly improved their tooling and techniques for detecting and analyzing the Cobalt Strike Beacon. As a response to this, some threat actors have shifted toward reimplementation of the Cobalt Strike Beacon written in modern programming languages such as Rust and Go. These new variants offer improved stealth, flexible customization, and inherent evasive characteristics originating from their language ecosystems.
This talk will present an in‑depth analysis of these emerging variants, exploring their architecture, behaviors, and notable samples observed in the wild. Additionally, we will offer practical strategies for blue teams, including configuration‑extraction methods and YARA detection rules designed to identify these new threats.
---
Naoki Takayama is a security researcher at Internet Initiative Japan, Inc. As a member of IIJ-SECT, the private CSIRT of his company, he is engaged in threat research and incident response. His research focuses on malware and tactics used in targeted attacks. He has spoken at BSides Tokyo and VB in the past.










