COBALTSPIN is a Rust-based network-tunneling malware used by the financially motivated BREEZE COMET threat actor. It establishes a reverse SOCKS5 proxy over WebSocket connections, bridging attacker-controlled infrastructure with internal targets across network boundaries and helping bypass internal firewall restrictions. BREEZE COMET has used COBALTSPIN with compromised privileged accounts to reach core financial applications and payment API infrastructure during fraud operations. The group primarily targets Brazilian banks, payment processors, retailers, fintech providers, exchanges, and other organizations able to submit transactions through Brazilian payment systems, including Pix, STR, and Boleto. COBALTSPIN supports persistent access to these internal environments and has been associated with campaigns that conducted fraudulent payment transactions before operators removed evidence of their activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The final stage involves using compromised accounts and tools like COBALTSPIN to execute fraudulent transactions and clear logs.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
COBALTSPIN... moves traffic through a reverse SOCKS5 proxy over WebSocket connections. BOATBEAM hides its traffic behind a fake HTTPS server.
COBALTSPIN, a Rust-based tunneling tool, moves traffic through a reverse SOCKS5 proxy over WebSocket connections.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool used by Breeze Comet during the fraud stage to execute unauthorized transactions and clear logs.
A Rust-based tunneling utility that provides reverse SOCKS5 proxying over WebSocket connections, enabling covert traffic routing and internal access. It was used with compromised privileged accounts to access core financial applications before fraudulent transfers.
Rust-based routing malware that establishes a reverse SOCKS5 proxy over WebSocket connections, enabling C2 communications and lateral movement through boundary firewalls. It is used to access financial applications and conduct fraudulent transactions.
Rust-based network tunneler providing a reverse SOCKS5 proxy over WebSocket, used to bypass internal firewalls and reach core financial applications through compromised privileged accounts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.