Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors EmpireMonkey

Also known as: CobaltGoblin, Empire Monkey

Description

**Notes:** Criminal, overlap with FIN7 & Carbanak

TTP Summary

Bank of Valletta

AI Analysis

· 1 week ago

Executive Summary

EmpireMonkey, also known as CobaltGoblin, is a nation-state level cyber threat actor primarily involved in espionage activities. They have demonstrated a significant focus on targeting financial institutions, leveraging sophisticated attack techniques and tools linked to criminal groups like FIN7 and Carbanak. Their activities pose a critical threat to global financial stability and sensitive data integrity.

Goals & Targeting

EmpireMonkey’s primary motivation appears to be espionage, with a focus on gathering intelligence and potentially disrupting financial operations. They target sectors known for holding sensitive data, such as banking and finance, indicating a strategic interest in economic and national security advantages. Their targeting of specific countries involved in financial transactions suggests an intent to compromise critical infrastructure and gain competitive economic intelligence.

Enhanced Description

EmpireMonkey is a nation-state threat actor known for their involvement in espionage and criminal activities, often overlapping with well-known groups such as FIN7 and Carbanak. They have been observed targeting financial sectors, including high-profile incidents like the Bank of Valletta attack. Their tactics, techniques, and procedures (TTPs) indicate a high level of sophistication, utilizing tools and methods similar to those employed by advanced persistent threat (APT) groups. EmpireMonkey's operations often involve targeted espionage campaigns aimed at extracting sensitive information from financial institutions.

Key Capabilities

  • Spear-phishing campaigns with malicious attachments
  • Use of custom malware for persistence and data exfiltration
  • Lateral movement within networks using legitimate-looking tools
  • Data theft and espionage targeting financial institutions

MITRE ATT&CK Tactics

Espionage: Reconnaissance
Initial Access
Execution
Defense Evasion
Credential Access
Lateral Movement
Exfiltration

ATT&CK Techniques

T1059.003 - Spear-phishing via email attachment with macros
T1055 - Non-proprietary tools for data dump
T1566.001 - Powershell for command and control (C2)
T1048 - Valid accounts

Software / Tooling

Cobalt Strike-like frameworks
Malicious Office documents with macros
Custom malware variants linked to FIN7/Carbanak
C2 infrastructure using HTTPS and fast-flux domains

Campaigns & Victims

EmpireMonkey's campaign patterns are characterized by targeted attacks on financial institutions, often involving prolonged network presence. They employ techniques such as spear-phishing, credential dumping, and persistence to achieve their objectives. Notable operations include the Bank of Valletta incident, which highlights their ability to infiltrate critical financial systems. Their operational tempo suggests they are active in multiple campaigns simultaneously, targeting high-value assets for long-term intelligence gathering.

IOC Patterns

  • Spear-phishing emails with malicious Office attachments
  • C2 communication over HTTPS or DNS tunnels
  • Presence of Cobalt Strike-like beacons
  • Use of custom domains mimicking financial institutions
  • Lateral movement using legitimate RDP or PS sessions

Recommended Actions

  • Implement advanced email filtering to detect spear-phishing attempts
  • Monitor network traffic for indicators of malicious C2 communication
  • Conduct regular security audits on financial systems
  • Enhance multi-factor authentication (MFA) for sensitive accounts
  • Ingest threat intelligence feeds focusing on EmpireMonkey's known IOCs

Suggested Tags

APT
espionage
financial-sector
banking

Confidence Assessment

There is a moderate confidence in EmpireMonkey's threat profile due to their overlap with well-documented actors like FIN7. While the specifics of their TTPs are not entirely clear, intelligence linking them to known campaigns provides a foundation for understanding their capabilities. Further analysis would benefit from additional IOCs and campaign details.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

1

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
espionage
financial-sector
banking

Details

Type
Nation-State
Resource Level
Unknown
Primary Motivation
Espionage
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.