Cobalt is a Windows-based malware toolkit in the Anunak/Carbanak lineage used in financially motivated intrusions against banks and other financial institutions. By late 2016, the tooling had evolved from earlier Anunak and Carbanak operations into the toolkit commonly tracked as Cobalt. It has been associated with attacks targeting ATM infrastructure, SWIFT and other payment systems, and broader bank internal networks.
Cobalt functions as a remote-access backdoor used to establish and maintain control over compromised systems inside financial environments. Reported capabilities in this lineage include remote control, keylogging, screen capture and screen-video recording, command-and-control communications over web protocols, transfer of additional files and tools, and movement to other internal systems to reach payment-processing, card-processing, and ATM-management assets. Operators have historically used prolonged post-compromise reconnaissance to observe employee workflows and imitate legitimate banking operations before monetization.
Intrusions associated with this malware family have relied on targeted spearphishing of bank employees, including weaponized Microsoft Office documents exploiting known vulnerabilities for initial execution. Once established, operators used the access to support fraudulent transfers, ATM cash-out schemes, and other bank-focused post-exploitation activity. The malware and tradecraft are closely associated with the broader Carbanak/Cobalt criminal ecosystem rather than a confirmed state-sponsored actor set.
Cobalt is best understood as a specialized financial-intrusion toolkit and successor stage in the Carbanak malware lineage, notable for enabling stealthy, hands-on-keyboard compromise of banking networks and payment operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In early 2015 a broader, more capable variant was documented under the name Carbanak, and by late 2016 the same lineage evolved again into the toolkit tracked as Cobalt.
1 distinct technique documented for this family, organized by ATT&CK tactic.
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A later evolution of the Anunak/Carbanak criminal malware lineage used in financial intrusions.
Referenced in campaign context as another malware/tool observed in the same cluster; functionality is not described in the content.
The domain is categorized as botnet command-and-control infrastructure associated with Trojan.Win32.Cobalt.
Malware/tool associated with attacks on banks, specifically targeting ATMs and SWIFT environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.