COBALT JUNO
Aliases: APT-C-38 (QiAnXin), SABER LION, TG-2884 (SCWX CTU)
- First seen
- 2013-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- nation-state
- Profile updated
- 2026-07-07 11:59:13
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:ir country_code:jo country_code:eg country_code:lb
Context
COBALT JUNO has operated since at least 2013 and focused on targets located in the Middle East including Iran, Jordan, Egypt & Lebanon. COBALT JUNO custom spyware families SABER1 and SABER2, include surveillance functionality and masquerade as legitimate software utilities such as Adobe Updater, StickyNote and ASKDownloader. CTU researchers assess with moderate confidence that COBALT JUNO operated the ZooPark Android spyware since at least mid-2015. ZooPark was publicly exposed in 2018 in both vendor reporting and a high profile leak of C2 server data. COBALT JUNO is linked to a private security company in Iran and outsources aspects of tool development work to commercial software developers. CTU researchers have observed the group using strategic web compromises to deliver malware. CTU researchers’ discovery of new C2 domains in 2019 suggest the group is still actively performing operations.
Reports & references
- secureworks.com — Cobalt Juno (report)