Cobalt Group is a financially motivated cybercrime threat actor widely associated with intrusions targeting banks, financial services organizations, payment systems, and other entities involved in card processing and cash-out operations. The group is commonly tracked under aliases including Cobalt Spider and Gold Kingswood, and has also been referred to as Cobalt Gang. Reporting has frequently linked the actor to Russian-speaking cybercriminal activity. Cobalt Group is known for conducting targeted spearphishing and follow-on post-compromise operations aimed at monetization, including theft from financial institutions and payment ecosystems. The actor has used a mix of custom malware, commodity tooling, and malware obtained from criminal service providers. Documented tooling and malware associated with the group include Cobalt Strike and JavaScript-based backdoors, and the group has also been observed using the More_eggs malware-as-a-service offering operated by Venom Spider/Golden Chickens. Observed tradecraft includes discovery of installed security products, PowerShell-based execution, process injection, exploitation for privilege escalation, and persistence through Windows autostart mechanisms such as Registry Run keys and Startup folder abuse. The group has also been associated with use of credential-stealing malware such as Pony, also known as Fareit or Siplog, in broader criminal operations. Across campaigns, Cobalt Group has demonstrated an ability to blend bespoke intrusion activity with widely available offensive tooling and malware services, enabling adaptable operations against enterprise environments with a strong emphasis on financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this threat actor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.