Skip to main content

Cybersecurity statistics / Cobalt Strike

China hosted 42.3% of all tracked Cobalt Strike infrastructure, the US hosted 18.9%, and Hong Kong hosted 15.8%.

PublisherBridewell
ReportCyber Threat Intelligence Report 2026
Published18 May 2026
TopicsCobalt Strike, China, US, Hong Kong

Published by Bridewell in Cyber Threat Intelligence Report 2026 , 18 May 2026. The figure is taken from the report as published; the full methodology is in the source.

View the original report

Related statistics

Cobalt Strike accounted for 38.4% of all OST output (3,944 of 10,272 tracked OST instances), maintaining its position as the primary adversary framework.
Bridewell, 27/05/2026
The most prevalent malware families observed in 2025 are Cobalt Strike, Sliver, Metasploit, Burp, PlugX, SuperShell C2, Havoc, Panda C2, Brute Ratel, and ShadowPad.
Bridewell, 27/05/2026
PowerShell was the primary attack vector with 96,061 detections by Trellix, followed by Cobalt Strike with 85,986 detections targeting the IT-to-OT boundary.
Trellix, 22/11/2025
BEAST threat actor leaked 700 GB of internal data from a large Chinese automotive group in late February 2026
PCA Cyber Security, 27/05/2026
China remained the second largest adversary infrastructure hosting location at 13.55%, down from 17.57% the previous year.
Bridewell, 27/05/2026
China's amended Cybersecurity Law took effect on 1 January 2026 (passed 28 October 2025) with raised penalties and extraterritorial reach
PCA Cyber Security, 27/05/2026

Get the newsletter

Weekly cybersecurity statistics by email.