Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Operation Cobalt Whisper

Operation Cobalt Whisper

TLP:CLEAR
Active

Also known as: Operation DreamJob, mauvehed, has traversed a long, winding, APT-C-35, Origami Elephant, Brainworm, APT32, Salt Typhoon, FamousSparrow, GhostEmperor, UNC2286, Deed RAT, Core Werewolf, Storm-0978, Tropical Scorpius, UNC2596, UNC4210, Asylum Ambuscade, Guildma, UNC4221, APT-K-47, primarily targeting Pakistani entities, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork

Description

Operation Cobalt Whisper represents a complex threat group whose public disclosures reveal a multi‑stage attack lifecycle combining social engineering, exploitation of software vulnerabilities, and persistent footholds via both commercial and custom tools. Initial access is almost exclusively achieved through spear‑phishing emails with malicious attachments—often disguised as RTF documents or ZIP archives—that contain LNK shortcuts designed to launch mshta.exe with obfuscated JavaScript payloads. Once executed, a PowerShell script downloads encrypted DLL binaries and extracts configuration information from embedded JSON files, enabling the attacker to tailor subsequent actions. The operators employ a domain generation algorithm (DGA) for backup command‑and‑control servers, ensuring continuity even when primary domains are taken down. In addition, they exploit well‑known public‑facing vulnerabilities such as ProxyLogon and FortiClient EMS to expand their reach or to achieve higher privileges on compromised systems. Persistence is achieved through the deployment of backdoors delivered via Cobalt Strike beacons or custom RATs like Deed RAT. The group also ships banking malware (Astaroth, Guildma) to victims in finance, telecom, and retail sectors, leveraging stolen credentials for credential stuffing or lateral movement. Defensive evasion tactics include PowerShell obfuscation, DLL injection, and the use of short‑lived scheduled tasks. Overall, Operation Cobalt Whisper’s operational pattern reflects a highly adaptive adversary that blends conventional APT techniques with targeted exploitation vectors to penetrate high‑value targets across diverse geographies.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Telecommunications
Non profit
Energy
Manufacturing
Education
Pharmaceutical
Healthcare
Transportation
Media
Aerospace
Maritime
Information technology
Critical infrastructure
Construction
Chemical
Think tank
Nuclear
Retail
Mining
Aviation
Food agriculture
Utilities
Gaming
Hospitality
Legal services
Entertainment

Targeted Countries / Regions

PK
US
CN
IN
DE
GB
JP
RU
KR
SA
TW
IR
TR
FR
CA
UA
VN
AU
IL
KZ
BR
PL
IT
AE
SG
NL
ES
IQ
BY
SY
MX
RO
EG
AZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 3 days ago

Executive Summary

Operation Cobalt Whisper is a sophisticated espionage APT that primarily targets government, military, and critical infrastructure organizations across multiple continents, with a notable focus on Pakistan and Latin American entities such as Brazil. The actor employs spear‑phishing campaigns using malicious LNK or RTF attachments, PowerShell scripts to download DLLs, and domain generation algorithms for resilient command and control. Their toolset includes Cobalt Strike beacons, custom RATs like Deed RAT, and banking malware such as Astaroth/Guildma.

Goals & Targeting

The primary strategic objective of Operation Cobalt Whisper is espionage—acquiring sensitive information from governmental, military, and critical infrastructure organizations worldwide. By targeting sectors such as defense, finance, telecommunications, energy, and healthcare, the actor seeks to harvest credentials, policy documents, and proprietary technology that can be leveraged for geopolitical advantage or economic exploitation.

Enhanced Description

Key Capabilities

  • Spear‑phishing via malicious LNK and RTF attachments
  • PowerShell-based execution to download and load DLLs
  • Extraction of configuration data from embedded JSON files
  • Use of Domain Generation Algorithm for backup C&C servers
  • Exploitation of public-facing vulnerabilities (e.g., ProxyLogon, FortiClient EMS)
  • Obfuscated JavaScript execution through mshta.exe
  • Delivery of banking‑malware such as Astaroth/Guildma
  • Deployment of custom RATs and backdoors (Cobalt Strike beacons, Deed RAT)

MITRE ATT&CK Tactics

Initial Access
Execution
Discovery
Command & Control
Defense Evasion

ATT&CK Techniques

T1566.001
T1059.003
T1105
T1190
T1071.004
T1218.005
T1027
T1071
T1053.005
T1033

Software / Tooling

Cobalt Strike
Deed RAT
Astaroth
Guildma

Campaigns & Victims

Operation Cobalt Whisper has demonstrated a campaign cadence that spans from initial spear‑phishing to long‑term persistence, with periods of heightened activity in targeted countries such as Pakistan and Brazil. The group shows an operational tempo that includes rapid patching of discovered vulnerabilities on victim systems using known exploits (e.g., ProxyLogon), paired with the deployment of stealthy backdoors for lateral movement. Their victims range across critical infrastructure, finance, telecom, and media sectors, indicating a broad asset map rather than single‑sector focus. The actor’s use of banking malware suggests dual objectives: immediate financial gain and long‑term data exfiltration.

IOC Patterns

  • Domain generation algorithm
  • Malicious LNK attachment disguised as RTF or ZIP
  • Suspicious DLL download via PowerShell
  • Obfuscated JavaScript execution using mshta.exe
  • C2 server communication from stolen credentials

Recommended Actions

  • Deploy email security solutions that block and quarantine malicious LNK, RTF, and ZIP attachments.
  • Enable comprehensive logging of PowerShell activity and monitor for anomalous download or execution commands.
  • Implement DNS‑based detection and blocking of DGA‑generated domains.
  • Apply timely patches for known software vulnerabilities, especially ProxyLogon and FortiClient EMS.
  • Use advanced endpoint protection with RAT/backdoor detection to identify Cobalt Strike beacons, Deed RAT, Astaroth, and Guildma malware.
  • Educate users about spear‑phishing risks, particularly regarding seemingly innocuous shortcut files and disguised attachments.

Suggested Tags

APT
Cobalt Strike
PowerShell
LNK attachment
Domain Generation Algorithm
Spear‑phishing
Exploits Public-Facing Application
Backdoor
Banking Malware
Latin America Targeted

Confidence Assessment

Moderate confidence. Several independent reports confirm the use of spear‑phishing LNK attachments, PowerShell execution, and DGA‑based C&C for Operation Cobalt Whisper. However, key details such as initial/last seen dates, precise attribution evidence, and complete infrastructure mapping are lacking. Further intelligence would be required to validate all claimed capabilities and fully map the group’s operational footprint.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

MD5 Hash 17 Filename 3

References

  1. ics-cert.kaspersky.com — Cited by web research for: APT-C-35
  2. thehackernews.com — Cited by web research for: APT-K-47
  3. misp-galaxy.org — Cited by web research for: cpyy
  4. www.seqrite.com — Cited by web research for: T1566.001
  5. rewterz.com — Cited by web research for: Media

Intel Summary

14

Techniques

43

Tools

0

Campaigns

40

IOCs

0

Observed Data

5

Tactics

Tags

APT
espionage
financial-sector
Cobalt Strike
PowerShell
LNK attachment
Domain Generation Algorithm
Spear‑phishing
Exploits Public-Facing Application
Backdoor
Banking Malware
Latin America Targeted

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.