Cobalt Group is a financially motivated cybercrime threat actor best known for intrusions targeting financial institutions, payment systems, and organizations that can be leveraged for fraud and cash-out operations. The group is widely tracked under multiple aliases including Cobalt, Cobalt Gang, Cobalt Spider, and Gold Kingswood. It has also been associated with use of commodity and shared criminal tooling, which can complicate attribution and overlap analysis with other financially motivated clusters. Cobalt Group has been linked to phishing-led initial access, post-compromise credential theft, lateral movement, persistence through Windows autorun mechanisms, and extensive use of process injection and other stealth techniques. Reporting has associated the group with malware and services such as Pony/Fareit and More_eggs in some operations or ecosystem relationships, reflecting its participation in broader cybercrime supply chains rather than a single exclusive malware platform. The actor has also been observed abusing legitimate administration utilities and common attacker tradecraft to blend into enterprise environments. Operationally, the group is known for targeting banks and related financial-sector entities, but its activity has also affected other enterprises where access can support monetization, follow-on intrusion activity, or malware delivery. Techniques repeatedly associated with the actor include PowerShell execution, exploitation for privilege escalation, process injection, and persistence via Registry Run keys or Startup-folder mechanisms. Cobalt Group is generally characterized as an e-crime actor rather than a nation-state operator, with objectives centered on financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
45 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
23 malware families attributed to this actor across reporting.
18 additional families tracked in Mallory.
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
After the latest update, MWI is now using CVE-2017-0199 to launch an HTML Application (HTA) used for both information collection and payload execution.
...has exploited Office vulnerabilities such as CVE-2017-11882...
Agent Tesla has exploited Office vulnerabilities such as CVE-2017-11882 and CVE-2017-8570 for execution during delivery.
...exploited... CVE-2017-8759.
Cobalt Group had exploited... an Internet Explorer vulnerability (CVE-2018-8174)...
3 more CVEs tied to this actor tracked in Mallory.
45 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an annotated threat actor associated with the ATT&CK technique Process Injection (T1055) in a Splunk detection entry; no campaign or activity is described.
Mentioned only as an annotation/tag associated with the ATT&CK technique Process Injection (T1055); no campaign or activity by this group is described in the content.
Mentioned only in an annotation/list associated with the detection content; no actor-specific activity is described in this reference.
Mentioned only in the detection annotation metadata; no campaign activity or actor-specific behavior is described in this content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.