Skip to main content
Mallory
MalwareRansomwareUsed by 2 actors

CobInt

CobInt is a backdoor/loader observed in campaigns targeting Russian organizations and associated in the provided reporting with ExCobalt (also referenced in overlap analysis as Shedding Zmiy/ExCobalt) and with the threat actor Crypt Ghouls. Kaspersky described CobInt as a “telltale tool” and identified it as a backdoor used by ExCobalt. In observed Crypt Ghouls intrusions, CobInt was used as a backdoor loader. The specific CobInt downloader described in the content was a VBScript named Intellpui.vbs that executed obfuscated PowerShell code, enabling malware to be loaded directly into memory without leaving traces on disk. The surrounding intrusion activity included abuse of compromised contractor and subcontractor credentials for VPN access, followed by use of tools such as NSSM and Localtonet for persistence and remote access, credential theft with Mimikatz and XenAllPasswordPro, and deployment of LockBit 3.0 on Windows and Babuk on Linux/ESXi. Related ExCobalt activity in the same reporting included attempts to steal Telegram credentials and message history and Outlook Web Access credentials. Victim organizations mentioned in connection with these campaigns included Russian businesses, government agencies, and entities in sectors such as mining, energy, finance, and retail. The only explicit CobInt-related filename/IOC in the content is Intellpui.vbs.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Crypt Ghouls

"...their use of CobInt, a backdoor loader... The CobInt downloader we encountered is a VBScript called Intellpui.vbs that executes obfuscated PowerShell code..."

via security online infosecurityonline.info
ExCobalt

...attempts to siphon Telegram credentials... and Outlook Web Access credentials... - CobInt, a known backdoor used by the group.

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

4 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

3 techniques
T1078Valid AccountsEvidence2

...threat actors leveraging a contractor's login credentials to connect to the internal systems via VPN... weaponizing trusted relationships.

T1189Drive-by CompromiseEvidence1

"...Outlook Web Access credentials by injecting malicious code into the login page..."

T1190Exploit Public-Facing ApplicationEvidence1

"...shifting the focus... from the exploitation of 1-day vulnerabilities in corporate services available from the internet (e.g., Microsoft Exchange)..."

Persistence

1 technique
T1078Valid AccountsEvidence2

...threat actors leveraging a contractor's login credentials to connect to the internal systems via VPN... weaponizing trusted relationships.

T1078Valid AccountsEvidence2

...threat actors leveraging a contractor's login credentials to connect to the internal systems via VPN... weaponizing trusted relationships.

Stealth

1 technique
T1078Valid AccountsEvidence2

...threat actors leveraging a contractor's login credentials to connect to the internal systems via VPN... weaponizing trusted relationships.

T1056.003Web Portal CaptureEvidence1

"...siphon... Outlook Web Access credentials by injecting malicious code into the login page..."

Collection

1 technique
T1056.003Web Portal CaptureEvidence1

"...siphon... Outlook Web Access credentials by injecting malicious code into the login page..."

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping4

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.