Cobalt Group
Cobalt Group, also referred to as Cobalt Gang, Cobalt Spider, and GOLD KINGSWOOD, is a cybercriminal threat group. Secureworks describes GOLD KINGSWOOD as a cybercriminal group that uses tactics more commonly associated with government-sponsored threat actors to infiltrate the internal networks of financial institutions around the globe. Reported activity in the provided content includes spearphishing emails sent to corporate and personal email accounts of victim organizations, including malicious attachments such as .rtf, .doc, .xls, LNK-containing archives, and password-protected archives containing .exe and .scr files; user-execution-dependent attachments requiring a file launch or macro execution; persistence via Registry Run keys, Startup path abuse to launch PowerShell and download Cobalt Strike, and creation of Windows scheduled tasks; execution via powershell.exe, JavaScript scriptlets, and a JavaScript backdoor capable of launching cmd.exe, with use of the Threadkit exploit toolkit to launch .bat files; lateral movement via Remote Desktop Protocol; command and control over HTTPS; SSH tunneling using Plink; network scanning with SoftPerfect Network Scanner; process injection into trusted processes; anti-forensic cleanup through deletion of a DLL dropper; and use of tools including Mimikatz, PsExec, Cobalt Strike, and SDelete.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Banks
- Financial Services
Where they target
Geographies tied to known operations.
- 🇷🇺 Russia
- 🇺🇦 Ukraine
Tradecraft
48 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
20 malware families attributed to this actor across reporting.
15 additional families tracked in Mallory.
Associated vulnerabilities
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
...has exploited Office vulnerabilities such as CVE-2017-11882...
...used exploits for... Word (CVE-2017-0199)...
Agent Tesla has exploited Office vulnerabilities such as CVE-2017-11882 and CVE-2017-8570 for execution during delivery.
...exploited... CVE-2017-8759.
Cobalt Group had exploited... an Internet Explorer vulnerability (CVE-2018-8174)...
2 more CVEs tied to this actor tracked in Mallory.
Observables
15 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed in the detection annotations as a threat actor associated with exploitation for privilege escalation.
Listed as a threat actor associated with the PowerShell P/Invoke process injection API chain detection and related ATT&CK techniques.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection analytic.
Referenced as a threat actor associated with the command obfuscation technique using environment variable substrings in Windows command lines.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.