Cobalt Group, also known as Cobalt, Cobalt Gang, Cobalt Spider, and GOLD KINGSWOOD, is a Russian-linked cybercrime group. The group has used spearphishing emails carrying malicious attachments, including Office documents, RTF files, archives, and disguised executables, to compromise organizational victims. It weaponized CVE-2017-11882 in malicious RTF delivery campaigns and has used Cobalt Strike as a post-compromise tool. Observed tradecraft includes PowerShell-based payload download and execution, execution of JavaScript scriptlets and Regsvr32-mediated scripts, and staging payloads on public file-hosting and code-hosting services for transfer to victim systems. Cobalt Group has established persistence through Windows Scheduled Tasks, Registry Run keys, and Startup-folder execution, including configurations that launch PowerShell to retrieve Cobalt Strike. It has also deleted a DLL dropper to reduce forensic evidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
30 malware families attributed to this actor across reporting.
25 additional families tracked in Mallory.
9 CVEs this actor has used in observed campaigns. 9 of them exploited in the wild.
A Microsoft Word attachment (sepa rules.doc) -- a ThreadKit exploit document that would exploit CVE-2017-8570, CVE-2017-11882, or CVE-2018-0802 -- to execute the embedded CobInt Stage 1 payload.
After the latest update, MWI is now using CVE-2017-0199 to launch an HTML Application (HTA) used for both information collection and payload execution.
A Microsoft Word attachment (sepa rules.doc) -- a ThreadKit exploit document that would exploit CVE-2017-8570, CVE-2017-11882, or CVE-2018-0802 -- to execute the embedded CobInt Stage 1 payload.
Giagone, R., Bermejo, L., and Yarochkin, F. (2017, November 20). Cobalt Strikes Again: Spam Runs Use Macros and CVE-2017-8759 Exploit Against Russian Banks.
The messages contained a Microsoft Word attachment that used a relationship object to download an external VBscript file containing an exploit for CVE-2018-8174 leading to the execution of CobInt stage 1.
4 more CVEs tied to this actor tracked in Mallory.
146 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed in the detection's Annotations section.
Mentioned only as an annotation associated with a detection for PYTHONPATH modification during package installation; no specific Cobalt Group activity is described.
Cobalt Group is listed only in the detection's annotations.
Cobalt Group is listed in the detection's annotations for Python site-hook creation during package installation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.