ATT&CKReferencesGroup IB Cobalt Aug 2017

Group IB Cobalt Aug 2017

Matveeva, V. (2017, August 15). Secrets of Cobalt. Retrieved October 10, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1021.001
Remote Desktop Protocol
GroupCobalt Group

Cobalt Group has used Remote Desktop Protocol to conduct lateral movement.

T1046
Network Service Discovery
GroupCobalt Group

Cobalt Group leveraged an open-source tool called SoftPerfect Network Scanner to perform network scanning.

T1053.005
Scheduled Task
GroupCobalt Group

Cobalt Group has created Windows tasks to establish persistence.

T1055
Process Injection
GroupCobalt Group

Cobalt Group has injected code into trusted processes.

T1059.001
PowerShell
GroupCobalt Group

Cobalt Group has used powershell.exe to download and execute scripts.

T1059.003
Windows Command Shell
GroupCobalt Group

Cobalt Group has used a JavaScript backdoor that is capable of launching cmd.exe to execute shell commands. The group has used an exploit toolkit known as Threadkit that launches .bat files.

T1059.005
Visual Basic
GroupCobalt Group

Cobalt Group has sent Word OLE compound documents with malicious obfuscated VBA macros that will run upon user execution.

T1059.007
JavaScript
GroupCobalt Group

Cobalt Group has executed JavaScript scriptlets on the victim's machine.

T1068
Exploitation for Privilege Escalation
GroupCobalt Group

Cobalt Group has used exploits to increase their levels of rights and privileges.

T1071.001
Web Protocols
GroupCobalt Group

Cobalt Group has used HTTPS for C2.

T1071.004
DNS
GroupCobalt Group

Cobalt Group has used DNS tunneling for C2.

T1219
Remote Access Tools
GroupCobalt Group

Cobalt Group used the Ammyy Admin tool as well as TeamViewer for remote access, including to preserve remote access if a Cobalt Strike module was lost.

T1543.003
Windows Service
GroupCobalt Group

Cobalt Group has created new services to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupCobalt Group

Cobalt Group has used Registry Run keys for persistence. The group has also set a Startup path to launch the PowerShell shell command and download Cobalt Strike.

T1548.002
Bypass User Account Control
GroupCobalt Group

Cobalt Group has bypassed UAC.

T1566.001
Spearphishing Attachment
GroupCobalt Group

Cobalt Group has sent spearphishing emails with various attachment types to corporate and personal email accounts of victim organizations. Attachment types have included .rtf, .doc, .xls, archives containing LNK files, and password protected archives containing .exe and .scr executables.

T1572
Protocol Tunneling
GroupCobalt Group

Cobalt Group has used the Plink utility to create SSH tunnels.

T1573.002
Asymmetric Cryptography
GroupCobalt Group

Cobalt Group has used the Plink utility to create SSH tunnels.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.