Also known as: Operation DreamJob, mauvehed, has traversed a long, winding, APT-C-35, Origami Elephant, Brainworm, APT32, Salt Typhoon, FamousSparrow, GhostEmperor, UNC2286, Deed RAT, Core Werewolf, Storm-0978, Tropical Scorpius, UNC2596, UNC4210, Asylum Ambuscade, Guildma, UNC4221, APT-K-47, primarily targeting Pakistani entities, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork
Operation Cobalt Whisper represents a complex threat group whose public disclosures reveal a multi‑stage attack lifecycle combining social engineering, exploitation of software vulnerabilities, and persistent footholds via both commercial and custom tools. Initial access is almost exclusively achieved through spear‑phishing emails with malicious attachments—often disguised as RTF documents or ZIP archives—that contain LNK shortcuts designed to launch mshta.exe with obfuscated JavaScript payloads. Once executed, a PowerShell script downloads encrypted DLL binaries and extracts configuration information from embedded JSON files, enabling the attacker to tailor subsequent actions. The operators employ a domain generation algorithm (DGA) for backup command‑and‑control servers, ensuring continuity even when primary domains are taken down. In addition, they exploit well‑known public‑facing vulnerabilities such as ProxyLogon and FortiClient EMS to expand their reach or to achieve higher privileges on compromised systems. Persistence is achieved through the deployment of backdoors delivered via Cobalt Strike beacons or custom RATs like Deed RAT. The group also ships banking malware (Astaroth, Guildma) to victims in finance, telecom, and retail sectors, leveraging stolen credentials for credential stuffing or lateral movement. Defensive evasion tactics include PowerShell obfuscation, DLL injection, and the use of short‑lived scheduled tasks. Overall, Operation Cobalt Whisper’s operational pattern reflects a highly adaptive adversary that blends conventional APT techniques with targeted exploitation vectors to penetrate high‑value targets across diverse geographies.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Operation Cobalt Whisper is a sophisticated espionage APT that primarily targets government, military, and critical infrastructure organizations across multiple continents, with a notable focus on Pakistan and Latin American entities such as Brazil. The actor employs spear‑phishing campaigns using malicious LNK or RTF attachments, PowerShell scripts to download DLLs, and domain generation algorithms for resilient command and control. Their toolset includes Cobalt Strike beacons, custom RATs like Deed RAT, and banking malware such as Astaroth/Guildma.
Goals & Targeting
The primary strategic objective of Operation Cobalt Whisper is espionage—acquiring sensitive information from governmental, military, and critical infrastructure organizations worldwide. By targeting sectors such as defense, finance, telecommunications, energy, and healthcare, the actor seeks to harvest credentials, policy documents, and proprietary technology that can be leveraged for geopolitical advantage or economic exploitation.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Operation Cobalt Whisper has demonstrated a campaign cadence that spans from initial spear‑phishing to long‑term persistence, with periods of heightened activity in targeted countries such as Pakistan and Brazil. The group shows an operational tempo that includes rapid patching of discovered vulnerabilities on victim systems using known exploits (e.g., ProxyLogon), paired with the deployment of stealthy backdoors for lateral movement. Their victims range across critical infrastructure, finance, telecom, and media sectors, indicating a broad asset map rather than single‑sector focus. The actor’s use of banking malware suggests dual objectives: immediate financial gain and long‑term data exfiltration.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence. Several independent reports confirm the use of spear‑phishing LNK attachments, PowerShell execution, and DGA‑based C&C for Operation Cobalt Whisper. However, key details such as initial/last seen dates, precise attribution evidence, and complete infrastructure mapping are lacking. Further intelligence would be required to validate all claimed capabilities and fully map the group’s operational footprint.
No campaigns linked yet.
No observed data linked yet.
14
Techniques
43
Tools
0
Campaigns
40
IOCs
0
Observed Data
5
Tactics