← threatfilter.dev / all groups / Cobalt Group
Cobalt Group
Also known as: GOLD KINGSWOOD · Cobalt Gang · Cobalt Spider
Overview
Cobalt Group is a financially motivated threat group that has primarily targeted financial institutions since at least 2016. The group has conducted intrusions to steal money via targeting ATM systems, card processing, payment systems and SWIFT systems. Cobalt Group has mainly targeted banks in Eastern Europe, Central Asia, and Southeast Asia. One of the alleged leaders was arrested in Spain in early 2018, but the group still appears to be active. The group has been known to target organizations in order to use their access to then compromise additional victims. Reporting indicates there may be links between Cobalt Group and both the malware Carbanak and the group Carbanak.
Capabilities
- Supply-chain compromise — ATT&CK T1195.002
- Exploitation of public-facing / client applications — ATT&CK T1203
- Custom malware/implant development — ATT&CK: 3 attributed custom malware families
TTPs — 34 techniques across 9 tactics
Resource Development
-
T1588.002Tool
Initial Access
-
T1195.002Compromise Software Supply Chain -
T1566.001Spearphishing Attachment -
T1566.002Spearphishing Link
Execution
-
T1053.005Scheduled Task -
T1059.001PowerShell -
T1059.003Windows Command Shell -
T1059.005Visual Basic -
T1059.007JavaScript -
T1203Exploitation for Client Execution -
T1204.001Malicious Link -
T1204.002Malicious File -
T1559.002Dynamic Data Exchange
Persistence
-
T1037.001Logon Script (Windows) -
T1543.003Windows Service -
T1547.001Registry Run Keys / Startup Folder
Privilege Escalation
-
T1068Exploitation for Privilege Escalation -
T1548.002Bypass User Account Control
Stealth
-
T1027.010Command Obfuscation -
T1055Process Injection -
T1070.004File Deletion -
T1218.003CMSTP -
T1218.008Odbcconf -
T1218.010Regsvr32 -
T1220XSL Script Processing
Discovery
-
T1046Network Service Discovery -
T1518.001Security Software Discovery
Lateral Movement
-
T1021.001Remote Desktop Protocol
Command and Control
-
T1071.001Web Protocols -
T1071.004DNS -
T1105Ingress Tool Transfer -
T1219Remote Access Tools -
T1572Protocol Tunneling -
T1573.002Asymmetric Cryptography
Tools & malware (6)
Mimikatz · More_eggs · SpicyOmelette · SDelete · Cobalt Strike · PsExec
Reporting (3)
- Cobalt Group 2.0 — Gorelik, M
- Cybercriminals Increasingly Trying to Ensnare the Big Financial Fish — CTU
- Multiple Cobalt Personality Disorder — Svajcer, V