Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Cobalt Group

Also known as: GOLD KINGSWOOD, Cobalt Gang, Cobalt Spider, Magecart Group 4, Cobalt Group, G0080, Mule Libra

Description

Cobalt Group is a financially motivated threat group that has primarily targeted financial institutions since at least 2016. The group has conducted intrusions to steal money via targeting ATM systems, card processing, payment systems and SWIFT systems. Cobalt Group has mainly targeted banks in Eastern Europe, Central Asia, and Southeast Asia. One of the alleged leaders was arrested in Spain in early 2018, but the group still appears to be active. The group has been known to target organizations in order to use their access to then compromise additional victims.(Citation: Talos Cobalt Group July 2018)(Citation: PTSecurity Cobalt Group Aug 2017)(Citation: PTSecurity Cobalt Dec 2016)(Citation: Group IB Cobalt Aug 2017)(Citation: Proofpoint Cobalt June 2017)(Citation: RiskIQ Cobalt Nov 2017)(Citation: RiskIQ Cobalt Jan 2018) Reporting indicates there may be links between Cobalt Group and both the malware Carbanak and the group Carbanak.(Citation: Europol Cobalt Mar 2018)

AI Analysis

· 1 week ago

Executive Summary

The Cobalt Group is a prominent cyber threat actor targeting financial institutions globally since at least 2016. Known for sophisticated attacks on financial systems, including ATM networks and SWIFT systems, the group primarily operates in Eastern Europe, Central Asia, and Southeast Asia despite leadership changes.

Goals & Targeting

The group targets financial institutions for monetary gain, focusing on regions with less robust cybersecurity measures. Their primary objectives include infiltrating banking systems to steal sensitive financial data and facilitate unauthorized transactions, leveraging their access to compromise additional victims.

Enhanced Description

Cobalt Group, also known as GOLD KINGSWOOD or Magecart Group 4, is a financially motivated cybercriminal group focusing on financial institutions. They employ advanced tactics to compromise ATM systems, card processing, and SWIFT networks. Originating from Eastern Europe and Central Asia, they have expanded their reach globally, including targeting banks in Southeast Asia. Notably linked to the Carbanak malware, Cobalt Group has proven resilient, continuing operations post-arrests of key members.

Key Capabilities

  • Advanced persistent threat (APT) tactics
  • Financial fraud through SWIFT and ATM systems
  • sophisticated malware deployment
  • Supply chain attacks

MITRE ATT&CK Tactics

Defense Evasion
Credential Access
Execution
Exfiltration

ATT&CK Techniques

T1053.005
T1059.007
T1204.002
T1566.002
T1055
T1572
T1218.008
T1059.001
T1027.010

Software / Tooling

SpicyOmelette
Cobalt Strike
More_eggs

Campaigns & Victims

The Cobalt Group is known for prolonged campaigns targeting financial sectors, using techniques like supply chain compromise and persistence mechanisms. Notable operations include attacks on banks in Eastern Europe and Southeast Asia.

IOC Patterns

  • Scheduled tasks created via Odbcconf.exe
  • Malicious files dropped during initial infection
  • Spear-phishing attachments

Recommended Actions

  • Monitor for scheduled tasks and unusual RDP activity
  • Implement APT detection policies
  • Secure SWIFT systems with MFA
  • Enhance software supply chain security

Suggested Tags

APT
financial sector
banking fraud

Confidence Assessment

Confidence is high in Cobalt Group's activities, though there are inconsistencies regarding their primary motivation (espionage vs. financial gain).

ATT&CK Techniques

Command & Control
6 techniques
Execution
9 techniques
Initial Access
3 techniques
Stealth
7 techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Crowdstrike Global Threat Report Feb 2018 — CrowdStrike. (2018, February 26). CrowdStrike 2018 Global Threat Report. Retrieved October 10, 2018.
  2. Secureworks GOLD KINGSWOOD September 2018 — CTU. (2018, September 27). Cybercriminals Increasingly Trying to Ensnare the Big Financial Fish. Retrieved September 20, 2021.
  3. Europol Cobalt Mar 2018 — Europol. (2018, March 26). Mastermind Behind EUR 1 Billion Cyber Bank Robbery Arrested in Spain. Retrieved October 10, 2018.
  4. Morphisec Cobalt Gang Oct 2018 — Gorelik, M. (2018, October 08). Cobalt Group 2.0. Retrieved November 5, 2018.
  5. RiskIQ Cobalt Nov 2017 — Klijnsma, Y.. (2017, November 28). Gaffe Reveals Full List of Targets in Spear Phishing Attack Using Cobalt Strike Against Financial Institutions. Retrieved October 10, 2018.
  6. RiskIQ Cobalt Jan 2018 — Klijnsma, Y.. (2018, January 16). First Activities of Cobalt Group in 2018: Spear Phishing Russian Banks. Retrieved October 10, 2018.
  7. Group IB Cobalt Aug 2017 — Matveeva, V. (2017, August 15). Secrets of Cobalt. Retrieved October 10, 2018.
  8. Proofpoint Cobalt June 2017 — Mesa, M, et al. (2017, June 1). Microsoft Word Intruder Integrates CVE-2017-0199, Utilized by Cobalt Group to Target Financial Institutions. Retrieved October 10, 2018.
  9. PTSecurity Cobalt Dec 2016 — Positive Technologies. (2016, December 16). Cobalt Snatch. Retrieved October 9, 2018.
  10. PTSecurity Cobalt Group Aug 2017 — Positive Technologies. (2017, August 16). Cobalt Strikes Back: An Evolving Multinational Threat to Finance. Retrieved September 5, 2018.
  11. Talos Cobalt Group July 2018 — Svajcer, V. (2018, July 31). Multiple Cobalt Personality Disorder. Retrieved September 5, 2018.

Intel Summary

34

Techniques

4

Tools

0

Campaigns

0

IOCs

0

Observed Data

9

Tactics

Tags

APT
Financial Targeting
financial sector
banking fraud

Details

MITRE ID
G0080
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--dc6fe6ee-04c2-49be-ba3d-f38d2463c02a
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.