Cobalt Group
MITRE ATT&CK: G0080 View on attack.mitre.org
Aliases: GOLD KINGSWOOD, Cobalt Gang, Cobalt Spider, Cobalt Group, COBALT SPIDER, Mule Libra
- First seen
- 2016-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- criminal
- Related IoCs
- 48
- Last IoC activity
- 2026-07-22 00:06:49
- Profile updated
- 2026-07-07 11:50:23
Targeted industries: financial-services
Targeted regions: country_code:ru country_code:ua country_code:pl country_code:kz country_code:sg
Context
Cobalt Group is a financially motivated threat group that has primarily targeted financial institutions since at least 2016. The group has conducted intrusions to steal money via targeting ATM systems, card processing, payment systems and SWIFT systems. Cobalt Group has mainly targeted banks in Eastern Europe, Central Asia, and Southeast Asia. One of the alleged leaders was arrested in Spain in early 2018, but the group still appears to be active. The group has been known to target organizations in order to use their access to then compromise additional victims. Reporting indicates there may be links between Cobalt Group and both the malware Carbanak and the group Carbanak.
Detection coverage
- 152 YARA rules
- 774 Sigma rules
Malware & tools used
- Spearphishing Attachment (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Command Obfuscation (attack-pattern)
- Scheduled Task (attack-pattern)
- Odbcconf (attack-pattern)
- Compromise Software Supply Chain (attack-pattern)
- Security Software Discovery (attack-pattern)
- Dynamic Data Exchange (attack-pattern)
- Malicious File (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
- CMSTP (attack-pattern)
- Regsvr32 (attack-pattern)
- Process Injection (attack-pattern)
- PowerShell (attack-pattern)
- Tool (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Visual Basic (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- File Deletion (attack-pattern)
- Bypass User Account Control (attack-pattern)
- XSL Script Processing (attack-pattern)
- DNS (attack-pattern)
- JavaScript (attack-pattern)
- Spearphishing Link (attack-pattern)
- Malicious Link (attack-pattern)
Exploited vulnerabilities
- CVE-2017-8759 (vulnerability)
- CVE-2017-0199 (vulnerability)
Reports & references
- europol.europa.eu — Mastermind Behind Eur 1 Billion Cyber Bank Robbery Arrested In Spain (report)
- computerweekly.com — Three Carbanak Cyber Heist Gang Members Arrested (report)
- helpnetsecurity.com — Cobalt Hackers Synchronized Atm Heists (report)
- bleepingcomputer.com — Cobalt Hacking Group Tests Banks In Russia And Romania (report)
- secureworks.com — Cybercriminals Increasingly Trying To Ensnare The Big Financial Fish (report)
- CrowdStrike — Meet Crowdstrikes Adversary Of The Month For September Cobalt Spider (report)
- group-ib.com — Cobalt (report)
- reuters.com — Taiwan Atm Heist Linked To European Hacking Spree Security Firm Iduskbn14P0Cx (report)
- proofpoint.com — Microsoft Word Intruder Integrates Cve 2017 0199 Utilized Cobalt Group Target (report)
- Trend Micro — Cobalt Spam Runs Use Macros Cve 2017 8759 Exploit (report)
- riskiq.com — Cobalt Strike (report)
- riskiq.com — Cobalt Group Spear Phishing Russian Banks (report)
- Palo Alto Unit 42 — Unit42 New Techniques Uncover Attribute Cobalt Gang Commodity Builders Infrastructure Revealed (report)
- ptsecurity.com — Cobalt 2017 Eng (report)
- MITRE ATT&CK — G0080 (report)
- secureworks.com — Gold Kingswood (report)
- Palo Alto Unit 42 — Mulelibra (report)
- blog.morphisec.com — Cobalt Gang 2.0 (report)
- Cisco Talos — Multiple Cobalt Personality Disorder (report)
- crowdstrike.lookbookhq.com — Cs 2018 Global Threat Report (report)
- web.archive.org — Cobalt Group Spear Phishing Russian Banks (report)
- web.archive.org — Cobalt Strike (report)
- ptsecurity.com — Cobalt Snatch Eng (report)
Attributed from
- 2023 Increased Truebot Activity (campaign)
- C0015 (campaign)
- FIN12 March 2023 Hospital Center Intrusion (campaign)
- May 2023 Exfiltration & Wiper Activity (Truebot + FlawedGrace + MBR Killer) (campaign)
- PaperCut Vulnerability Exploitation (campaign)
- Pikabot Distribution Campaigns 2023 (campaign)
- Quantum Ransomware Compromise (campaign)
- Water Curupira Pikabot Distribution (campaign)
External references
- mitre-attack — G0080
- Cobalt Spider
- GOLD KINGSWOOD
- Cobalt Gang
- Cobalt Group
- Crowdstrike Global Threat Report Feb 2018
- Secureworks GOLD KINGSWOOD September 2018
- Europol Cobalt Mar 2018
- Morphisec Cobalt Gang Oct 2018
- RiskIQ Cobalt Nov 2017
- RiskIQ Cobalt Jan 2018
- Group IB Cobalt Aug 2017
- Proofpoint Cobalt June 2017
- PTSecurity Cobalt Dec 2016
- PTSecurity Cobalt Group Aug 2017
- Talos Cobalt Group July 2018
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy