CobInt

Aliases: COOLPANTS

First seen
2018-01-01 00:00:00
Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 12:40:24

Targeted industries: financial-services government-and-public-sector

Targeted regions: country_code:us country_code:ru

Context

CobInt, is a self-developed backdoor of the Cobalt group. The modular tool has capabilities to collect initial intelligence information about the compromised machine and stream video from its desktop. If the operator decides that the system is of interest, the backdoor will download and launch CobaltStrike framework stager. It's CRM mailslot module was also observed being downloaded by ISFB.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Cobint_Auto (yara-rule)

Reports & references

  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • secureworks.com — Gold Kingswood (report)
  • pwc.co.uk — Cyber Threats 2019 Retrospect (report)
  • asert.arbornetworks.com — Double The Infection Double The Fun (report)
  • secureworks.com — Gold Kingswood (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Cobint (report)
  • ptsecurity.com — Cobalt Upd Ttps (report)
  • group-ib.com — Renaissance (report)
  • netscout.com — Double Infection Double Fun (report)
  • proofpoint.com — New Modular Downloaders Fingerprint Systems Part 3 Cobint (report)

External references