Also known as: CobaltGoblin, Empire Monkey
**Notes:** Criminal, overlap with FIN7 & Carbanak
Bank of Valletta
Executive Summary
EmpireMonkey, also known as CobaltGoblin, is a nation-state level cyber threat actor primarily involved in espionage activities. They have demonstrated a significant focus on targeting financial institutions, leveraging sophisticated attack techniques and tools linked to criminal groups like FIN7 and Carbanak. Their activities pose a critical threat to global financial stability and sensitive data integrity.
Goals & Targeting
EmpireMonkey’s primary motivation appears to be espionage, with a focus on gathering intelligence and potentially disrupting financial operations. They target sectors known for holding sensitive data, such as banking and finance, indicating a strategic interest in economic and national security advantages. Their targeting of specific countries involved in financial transactions suggests an intent to compromise critical infrastructure and gain competitive economic intelligence.
Enhanced Description
EmpireMonkey is a nation-state threat actor known for their involvement in espionage and criminal activities, often overlapping with well-known groups such as FIN7 and Carbanak. They have been observed targeting financial sectors, including high-profile incidents like the Bank of Valletta attack. Their tactics, techniques, and procedures (TTPs) indicate a high level of sophistication, utilizing tools and methods similar to those employed by advanced persistent threat (APT) groups. EmpireMonkey's operations often involve targeted espionage campaigns aimed at extracting sensitive information from financial institutions.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
EmpireMonkey's campaign patterns are characterized by targeted attacks on financial institutions, often involving prolonged network presence. They employ techniques such as spear-phishing, credential dumping, and persistence to achieve their objectives. Notable operations include the Bank of Valletta incident, which highlights their ability to infiltrate critical financial systems. Their operational tempo suggests they are active in multiple campaigns simultaneously, targeting high-value assets for long-term intelligence gathering.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
There is a moderate confidence in EmpireMonkey's threat profile due to their overlap with well-documented actors like FIN7. While the specifics of their TTPs are not entirely clear, intelligence linking them to known campaigns provides a foundation for understanding their capabilities. Further analysis would benefit from additional IOCs and campaign details.
No techniques linked yet.
No tools linked yet.
Bank of Valletta
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
1
Campaigns
0
IOCs
0
Observed Data
0
Tactics