ATT&CKGroupsCobalt Group

Cobalt Group

G0080

Threat group.View on attack.mitre.org

About this group

Cobalt Group is a financially motivated threat group that has primarily targeted financial institutions since at least 2016. The group has conducted intrusions to steal money via targeting ATM systems, card processing, payment systems and SWIFT systems. Cobalt Group has mainly targeted banks in Eastern Europe, Central Asia, and Southeast Asia. One of the alleged leaders was arrested in Spain in early 2018, but the group still appears to be active. The group has been known to target organizations in order to use their access to then compromise additional victims. Reporting indicates there may be links between Cobalt Group and both the malware Carbanak and the group Carbanak.

Techniques used34

Procedure examples34

TechniqueProcedure example
T1021.001
Remote Desktop Protocol

Cobalt Group has used Remote Desktop Protocol to conduct lateral movement.

T1027.010
Command Obfuscation

Cobalt Group obfuscated several scriptlets and code used on the victim’s machine, including through use of XOR and RC4.

T1037.001
Logon Script (Windows)

Cobalt Group has added persistence by registering the file name for the next stage malware under HKCU\Environment\UserInitMprLogonScript.

T1046
Network Service Discovery

Cobalt Group leveraged an open-source tool called SoftPerfect Network Scanner to perform network scanning.

T1053.005
Scheduled Task

Cobalt Group has created Windows tasks to establish persistence.

T1055
Process Injection

Cobalt Group has injected code into trusted processes.

T1059.001
PowerShell

Cobalt Group has used powershell.exe to download and execute scripts.

T1059.003
Windows Command Shell

Cobalt Group has used a JavaScript backdoor that is capable of launching cmd.exe to execute shell commands. The group has used an exploit toolkit known as Threadkit that launches .bat files.

T1059.005
Visual Basic

Cobalt Group has sent Word OLE compound documents with malicious obfuscated VBA macros that will run upon user execution.

T1059.007
JavaScript

Cobalt Group has executed JavaScript scriptlets on the victim's machine.

T1068
Exploitation for Privilege Escalation

Cobalt Group has used exploits to increase their levels of rights and privileges.

T1070.004
File Deletion

Cobalt Group deleted the DLL dropper from the victim’s machine to cover their tracks.

T1071.001
Web Protocols

Cobalt Group has used HTTPS for C2.

T1071.004
DNS

Cobalt Group has used DNS tunneling for C2.

T1105
Ingress Tool Transfer

Cobalt Group has used public sites such as github.com and sendspace.com to upload files and then download them to victim computers. The group's JavaScript backdoor is also capable of downloading files.

View all 34 procedure examples

Software6

Campaigns0

None recorded.

References8

  1. Europol Cobalt Mar 2018 Open source
    Europol. (2018, March 26). Mastermind Behind EUR 1 Billion Cyber Bank Robbery Arrested in Spain. Retrieved October 10, 2018.
  2. Group IB Cobalt Aug 2017 Open source
    Matveeva, V. (2017, August 15). Secrets of Cobalt. Retrieved October 10, 2018.
  3. PTSecurity Cobalt Dec 2016 Open source
    Positive Technologies. (2016, December 16). Cobalt Snatch. Retrieved October 9, 2018.
  4. PTSecurity Cobalt Group Aug 2017 Open source
    Positive Technologies. (2017, August 16). Cobalt Strikes Back: An Evolving Multinational Threat to Finance. Retrieved September 5, 2018.
  5. Proofpoint Cobalt June 2017 Open source
    Mesa, M, et al. (2017, June 1). Microsoft Word Intruder Integrates CVE-2017-0199, Utilized by Cobalt Group to Target Financial Institutions. Retrieved October 10, 2018.
  6. RiskIQ Cobalt Jan 2018 Open source
    Klijnsma, Y.. (2018, January 16). First Activities of Cobalt Group in 2018: Spear Phishing Russian Banks. Retrieved October 10, 2018.
  7. RiskIQ Cobalt Nov 2017 Open source
    Klijnsma, Y.. (2017, November 28). Gaffe Reveals Full List of Targets in Spear Phishing Attack Using Cobalt Strike Against Financial Institutions. Retrieved October 10, 2018.
  8. Talos Cobalt Group July 2018 Open source
    Svajcer, V. (2018, July 31). Multiple Cobalt Personality Disorder. Retrieved September 5, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.