Positive Technologies. (2017, August 16). Cobalt Strikes Back: An Evolving Multinational Threat to Finance. Retrieved September 5, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1046 Network Service Discovery |
GroupCobalt Group | Cobalt Group leveraged an open-source tool called SoftPerfect Network Scanner to perform network scanning. |
| T1059.001 PowerShell |
GroupCobalt Group | Cobalt Group has used powershell.exe to download and execute scripts. |
| T1059.003 Windows Command Shell |
GroupCobalt Group | Cobalt Group has used a JavaScript backdoor that is capable of launching cmd.exe to execute shell commands. The group has used an exploit toolkit known as Threadkit that launches .bat files. |
| T1059.005 Visual Basic |
GroupCobalt Group | Cobalt Group has sent Word OLE compound documents with malicious obfuscated VBA macros that will run upon user execution. |
| T1059.007 JavaScript |
GroupCobalt Group | Cobalt Group has executed JavaScript scriptlets on the victim's machine. |
| T1105 Ingress Tool Transfer |
GroupCobalt Group | Cobalt Group has used public sites such as github.com and sendspace.com to upload files and then download them to victim computers. The group's JavaScript backdoor is also capable of downloading files. |
| T1203 Exploitation for Client Execution |
GroupCobalt Group | Cobalt Group had exploited multiple vulnerabilities for execution, including Microsoft’s Equation Editor (CVE-2017-11882), an Internet Explorer vulnerability (CVE-2018-8174), CVE-2017-8570, CVE-2017-0199, and CVE-2017-8759. |
| T1219 Remote Access Tools |
GroupCobalt Group | Cobalt Group used the Ammyy Admin tool as well as TeamViewer for remote access, including to preserve remote access if a Cobalt Strike module was lost. |
| T1566.001 Spearphishing Attachment |
GroupCobalt Group | Cobalt Group has sent spearphishing emails with various attachment types to corporate and personal email accounts of victim organizations. Attachment types have included .rtf, .doc, .xls, archives containing LNK files, and password protected archives containing .exe and .scr executables. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.