CobInt
Aliases: COOLPANTS
- First seen
- 2018-01-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Profile updated
- 2026-07-07 12:40:24
Targeted industries: financial-services government-and-public-sector
Targeted regions: country_code:us country_code:ru
Context
CobInt, is a self-developed backdoor of the Cobalt group. The modular tool has capabilities to collect initial intelligence information about the compromised machine and stream video from its desktop. If the operator decides that the system is of interest, the backdoor will download and launch CobaltStrike framework stager. It's CRM mailslot module was also observed being downloaded by ISFB.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Cobint_Auto (yara-rule)
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- secureworks.com — Gold Kingswood (report)
- pwc.co.uk — Cyber Threats 2019 Retrospect (report)
- asert.arbornetworks.com — Double The Infection Double The Fun (report)
- secureworks.com — Gold Kingswood (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Cobint (report)
- ptsecurity.com — Cobalt Upd Ttps (report)
- group-ib.com — Renaissance (report)
- netscout.com — Double Infection Double Fun (report)
- proofpoint.com — New Modular Downloaders Fingerprint Systems Part 3 Cobint (report)