Cobalt Group
Also known as: GOLD KINGSWOOD · Cobalt Gang · Cobalt Spider
Overview
Cobalt Group is a financially motivated threat group that has primarily targeted financial institutions since at least 2016. The group has conducted intrusions to steal money via targeting ATM systems, card processing, payment systems and SWIFT systems. Cobalt Group has mainly targeted banks in Eastern Europe, Central Asia, and Southeast Asia. One of the alleged leaders was arrested in Spain in early 2018, but the group still appears to be active. The group has been known to target organizations in order to use their access to then compromise additional victims. Reporting indicates there may be links between Cobalt Group and both the malware Carbanak and the group Carbanak.
Naming & attribution
Cobalt Group is tracked under 4 names across the industry. It uses 34 documented ATT&CK techniques — more than 70% of the 174 groups tracked here. Activity attributed since at least 2016.
| Name | First reported by |
|---|---|
| GOLD KINGSWOOD | CTU |
| Cobalt Gang | Svajcer, V |
| Cobalt Spider | CrowdStrike |
| Cobalt Group | Svajcer, V |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1218.008Odbcconf — used by 1 of 174 groups -
T1037.001Logon Script (Windows) — used by 2 of 174 groups -
T1218.003CMSTP — used by 2 of 174 groups -
T1220XSL Script Processing — used by 2 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Patchwork — 18 shared techniques (32% overlap)
- FIN8 — 16 shared techniques (30% overlap)
- Silence — 14 shared techniques (29% overlap)
- LazyScripter — 12 shared techniques (29% overlap)
- Sidewinder India — 14 shared techniques (28% overlap)
- TA2541 — 13 shared techniques (27% overlap)
Capabilities
- Supply-chain compromise — ATT&CK T1195.002
- Exploitation of public-facing / client applications — ATT&CK T1203
- Custom malware/implant development — ATT&CK: 3 attributed custom malware families
TTPs — 34 techniques across 9 tactics
Resource Development
-
T1588.002Tool
Initial Access
-
T1195.002Compromise Software Supply Chain -
T1566.001Spearphishing Attachment -
T1566.002Spearphishing Link
Execution
-
T1053.005Scheduled Task -
T1059.001PowerShell -
T1059.003Windows Command Shell -
T1059.005Visual Basic -
T1059.007JavaScript -
T1203Exploitation for Client Execution -
T1204.001Malicious Link -
T1204.002Malicious File -
T1559.002Dynamic Data Exchange
Persistence
-
T1037.001Logon Script (Windows) -
T1543.003Windows Service -
T1547.001Registry Run Keys / Startup Folder
Privilege Escalation
-
T1068Exploitation for Privilege Escalation -
T1548.002Bypass User Account Control
Stealth
-
T1027.010Command Obfuscation -
T1055Process Injection -
T1070.004File Deletion -
T1218.003CMSTP -
T1218.008Odbcconf -
T1218.010Regsvr32 -
T1220XSL Script Processing
Discovery
-
T1046Network Service Discovery -
T1518.001Security Software Discovery
Lateral Movement
-
T1021.001Remote Desktop Protocol
Command and Control
-
T1071.001Web Protocols -
T1071.004DNS -
T1105Ingress Tool Transfer -
T1219Remote Access Tools -
T1572Protocol Tunneling -
T1573.002Asymmetric Cryptography
Tools & malware (6)
Mimikatz · More_eggs · SpicyOmelette · SDelete · Cobalt Strike · PsExec
Reporting (3)
- Cobalt Group 2.0 — Gorelik, M
- Cybercriminals Increasingly Trying to Ensnare the Big Financial Fish — CTU
- Multiple Cobalt Personality Disorder — Svajcer, V