Also known as: APT44, Seashell Blizzard, Storm-0978, Tropical Scorpius, Onyx Sleet, Storm-1789, APT36, ProjectM, Mythic Leopard, Earth Karkaddan, BRONZE VINEWOOD, Judgment Panda, Zirconium, Stately Taurus, Bronze President, Earth Preta, HoneyMyte, Camaro Dragon, RedDelta, Mango Sandstorm, Boggy Serpens, Strontium, Fancy Bear, Carbon Spider, Elbrus, Sangria Tempest, BlackEnergy, PHANTOM, Blue Echidna, Void Rabisu, UNC2596, SHADOW-VOID-042, RomCom, the Bulldog backdoor, GOFFEE, Fluffy Wolf, Smoke Sandstorm, TA455, Yellow Liderc, Tortoiseshell, ZIRCONIUM, JUDGMENT PANDA, Red keres, Violet Typhoon, TA412, TIDE CASTLE, Imperial Kitten, LuoYu, CASCADE PANDA, Qilin, file transfer tools, UNC6619
ExCobalt is a highly adaptable APT group that originated from the notorious Cobalt Gang network. The threat actor operates globally, with documented campaigns against government, military, critical‑infrastructure, and corporate IT environments in Russia, Ukraine, the United States, China, Israel, and other regions. Its toolkit blends custom‑compiled Golang modules (e.g., GoRed), commercial RATs like Cobalt Strike, and an array of open‑source utilities such as Mimikatz for credential dumping, ZeroLot/Wiper payloads, and Process Hollowing techniques. Operationally, ExCobalt relies on a multi‑stage delivery chain that starts with spear‑phishing or social‑engineering emails containing malicious attachments (DOCX, LNK, HTA, ISO) or cloud links. These deliver obfuscated PowerShell loaders or JavaScript exploiting browser CVEs to achieve execution. Upon compromise the group escalates privileges using Windows Print Spooler CVE‑2022‑38028 and Linux kernel exploits on maritime DVR devices (CVE‑2024‑3721), establishing persistence via scheduled tasks, Run keys, or process hollowing into benign programs such as MSBuild.exe. The adversary’s final objectives span data theft, sabotage, and opportunistic disruption. ExCobalt frequently deploys data wiping wipers like ZeroLot and Sting via Group Policy changes to remove evidence, while occasionally leveraging the Broadside botnet for DDoS attacks against maritime logistics networks. The group’s capability to modify standard utilities (e.g., custom Cobalt Strike profiles, magic‑header C2 traffic) demonstrates an ongoing evolution toward stealth, evasion of EDR solutions, and prolonged persistence.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
ExCobalt (also known as APT44, Storm-0978, and Cobalt Gang affiliates) is an advanced persistent threat that has operated since at least 2016, targeting a wide range of sectors across the globe with sophisticated supply‑chain and credential‑stealing campaigns. The group leverages custom Golang backdoors such as GoRed together with known tools like Cobalt Strike, Mimikatz, and ZeroLot/Wipers to conduct data exfiltration, sabotage, and persistent compromise. Current analysis shows a shift toward exploiting publicly disclosed CVEs (e.g., Windows Print Spooler CVE‑2022‑38028, Office/.NET CVEs) and delivering payloads via Office macros, PDFs, ISO images, and cloud services for initial access.
Goals & Targeting
ExCobalt aims to extract classified or proprietary information from high‑value targets that can influence geopolitical advantage or economic competition. The actor prioritizes government entities, defense contractors, critical infrastructure, financial services, manufacturing, and technology firms—organizations with extensive data assets and exposure to supply‑chain vulnerabilities. By combining credential theft, remote execution, and persistent backdoors, ExCobalt facilitates long‑term espionage operations while also injecting sabotage motives evident in its wiper deployments and sporadic ransomware or DDoS campaigns.
Enhanced Description
Key Capabilities
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
0
Tactics