COBALT JUNO

Aliases: APT-C-38 (QiAnXin), SABER LION, TG-2884 (SCWX CTU)

First seen
2013-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
organization
Actor type
nation-state
Profile updated
2026-07-07 11:59:13

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:ir country_code:jo country_code:eg country_code:lb

Context

COBALT JUNO has operated since at least 2013 and focused on targets located in the Middle East including Iran, Jordan, Egypt & Lebanon. COBALT JUNO custom spyware families SABER1 and SABER2, include surveillance functionality and masquerade as legitimate software utilities such as Adobe Updater, StickyNote and ASKDownloader. CTU researchers assess with moderate confidence that COBALT JUNO operated the ZooPark Android spyware since at least mid-2015. ZooPark was publicly exposed in 2018 in both vendor reporting and a high profile leak of C2 server data. COBALT JUNO is linked to a private security company in Iran and outsources aspects of tool development work to commercial software developers. CTU researchers have observed the group using strategic web compromises to deliver malware. CTU researchers’ discovery of new C2 domains in 2019 suggest the group is still actively performing operations.

Reports & references

  • secureworks.com — Cobalt Juno (report)

External references