Cobalt Group — APT Profile
Cobalt Group is a financially motivated threat group that has primarily targeted financial institutions since at least 2016. The group has conducted intrusions to steal money via targeting ATM systems, card processing, payment systems and SWIFT systems. Cobalt Group has mainly targeted banks in Eastern Europe, Central Asia, and Southeast Asia. One of the alleged leaders was arrested in Spain in early 2018, but the group still appears to be active. The group has been known to target organizations in order to use their access to then compromise additional victims. Reporting indicates there may be links between Cobalt Group and both the malware Carbanak and the group Carbanak.Also tracked as
GOLD KINGSWOOD, Cobalt Gang, Cobalt Spider
Tools & malware
- Cobalt Strike Adversary Simulation
- Mimikatz Credential Harvesting
- More_eggs Backdoor
- PsExec Remote Execution
- SDelete Defense Evasion
- SpicyOmelette Backdoor
Vendor research
- Cybercriminals Increasingly Trying to Ensnare the Big Financial Fish CTU
- Mastermind Behind EUR 1 Billion Cyber Bank Robbery Arrested in Spain Europol
- Cobalt Group 2.0 Morphisec
- Gaffe Reveals Full List of Targets in Spear Phishing Attack Using Cobalt Strike Against Financial Institutions RiskIQ
- First Activities of Cobalt Group in 2018: Spear Phishing Russian Banks RiskIQ
- Secrets of Cobalt Group IB
- Microsoft Word Intruder Integrates CVE-2017-0199, Utilized by Cobalt Group to Target Financial Institutions Proofpoint
- Cobalt Snatch PTSecurity
- Cobalt Strikes Back: An Evolving Multinational Threat to Finance PTSecurity
- Multiple Cobalt Personality Disorder Talos
- CrowdStrike 2018 Global Threat Report Crowdstrike
- Cybercriminals Increasingly Trying to Ensnare the Big Financial Fish Secureworks