Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ExCobalt

Also known as: APT44, Seashell Blizzard, Storm-0978, Tropical Scorpius, Onyx Sleet, Storm-1789, APT36, ProjectM, Mythic Leopard, Earth Karkaddan, BRONZE VINEWOOD, Judgment Panda, Zirconium, Stately Taurus, Bronze President, Earth Preta, HoneyMyte, Camaro Dragon, RedDelta, Mango Sandstorm, Boggy Serpens, Strontium, Fancy Bear, Carbon Spider, Elbrus, Sangria Tempest, BlackEnergy, PHANTOM, Blue Echidna, Void Rabisu, UNC2596, SHADOW-VOID-042, RomCom, the Bulldog backdoor, GOFFEE, Fluffy Wolf, Smoke Sandstorm, TA455, Yellow Liderc, Tortoiseshell, ZIRCONIUM, JUDGMENT PANDA, Red keres, Violet Typhoon, TA412, TIDE CASTLE, Imperial Kitten, LuoYu, CASCADE PANDA, Qilin, file transfer tools, UNC6619

Description

ExCobalt is a highly adaptable APT group that originated from the notorious Cobalt Gang network. The threat actor operates globally, with documented campaigns against government, military, critical‑infrastructure, and corporate IT environments in Russia, Ukraine, the United States, China, Israel, and other regions. Its toolkit blends custom‑compiled Golang modules (e.g., GoRed), commercial RATs like Cobalt Strike, and an array of open‑source utilities such as Mimikatz for credential dumping, ZeroLot/Wiper payloads, and Process Hollowing techniques. Operationally, ExCobalt relies on a multi‑stage delivery chain that starts with spear‑phishing or social‑engineering emails containing malicious attachments (DOCX, LNK, HTA, ISO) or cloud links. These deliver obfuscated PowerShell loaders or JavaScript exploiting browser CVEs to achieve execution. Upon compromise the group escalates privileges using Windows Print Spooler CVE‑2022‑38028 and Linux kernel exploits on maritime DVR devices (CVE‑2024‑3721), establishing persistence via scheduled tasks, Run keys, or process hollowing into benign programs such as MSBuild.exe. The adversary’s final objectives span data theft, sabotage, and opportunistic disruption. ExCobalt frequently deploys data wiping wipers like ZeroLot and Sting via Group Policy changes to remove evidence, while occasionally leveraging the Broadside botnet for DDoS attacks against maritime logistics networks. The group’s capability to modify standard utilities (e.g., custom Cobalt Strike profiles, magic‑header C2 traffic) demonstrates an ongoing evolution toward stealth, evasion of EDR solutions, and prolonged persistence.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Manufacturing
Transportation
Critical infrastructure
Energy
Aerospace
Telecommunications
Education
Pharmaceutical
Mining
Construction
Aviation
Healthcare
Maritime
Food agriculture
Retail
Media
Utilities
Information technology
Chemical
Hospitality
Nuclear
Oil gas
Entertainment

Targeted Countries / Regions

RU
US
CN
UA
TW
IN
KR
IL
BY
DE
BR
MX
TR
EG
IT
IR
FR
CA
GB
PL
VN
SA
JP
NG

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

ExCobalt (also known as APT44, Storm-0978, and Cobalt Gang affiliates) is an advanced persistent threat that has operated since at least 2016, targeting a wide range of sectors across the globe with sophisticated supply‑chain and credential‑stealing campaigns. The group leverages custom Golang backdoors such as GoRed together with known tools like Cobalt Strike, Mimikatz, and ZeroLot/Wipers to conduct data exfiltration, sabotage, and persistent compromise. Current analysis shows a shift toward exploiting publicly disclosed CVEs (e.g., Windows Print Spooler CVE‑2022‑38028, Office/​.NET CVEs) and delivering payloads via Office macros, PDFs, ISO images, and cloud services for initial access.

Goals & Targeting

ExCobalt aims to extract classified or proprietary information from high‑value targets that can influence geopolitical advantage or economic competition. The actor prioritizes government entities, defense contractors, critical infrastructure, financial services, manufacturing, and technology firms—organizations with extensive data assets and exposure to supply‑chain vulnerabilities. By combining credential theft, remote execution, and persistent backdoors, ExCobalt facilitates long‑term espionage operations while also injecting sabotage motives evident in its wiper deployments and sporadic ransomware or DDoS campaigns.

Enhanced Description

Key Capabilities

  • Office macro and .NET CVE exploitation for initial access
  • Delivery of HTA, LNK, RFC, ISO image documents via cloud services or phishing emails
  • Obfuscated PowerShell loaders that decrypt shellcode entirely in memory
  • Golang/Python/Rust cross‑platform espionage suites (including GoRed backdoor)
  • Credential harvesting via Print Spooler CVE‑2022‑38028 and Linux passwd/shadow reading on DVR devices
  • Data exfiltration with custom TLS or Netlink kernel sockets
  • Scheduled task creation, Run key modification, and Group Policy changes for persistence
  • Process hollowing into MSBuild.exe for defense evasion
  • Wiper payloads (ZEROLOT, Sting) delivered through scheduled tasks
  • Command‑injection exploitation of TBK Vision DVR CVE‑2024‑3721 to execute commands and steal credentials
  • Broadside botnet‑style DDoS attacks against maritime infrastructure
  • Custom C2 traffic using unique magic header 0x36694201 over TCP

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. ics-cert.kaspersky.com — Cited by web research for: APT44
  2. ics-cert.kaspersky.com — Cited by web research for: Storm-0978
  3. apt.etda.or.th — Cited by web research for: Phishing emails
  4. unit42.paloaltonetworks.com — Cited by web research for: WildFire

Intel Summary

0

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
Critical Infrastructure
Supply Chain Attack
Phishing
Backdoor / C2
Data Exfiltration
Government Targeting
Espionage
Russia-aligned
Cobalt Gang
Cyberespionage

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
Russia (RU)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.