Also known as: GOLD KINGSWOOD, Cobalt Gang, Cobalt Spider, Magecart Group 4, Cobalt Group, G0080, Mule Libra
Cobalt Group is a financially motivated threat group that has primarily targeted financial institutions since at least 2016. The group has conducted intrusions to steal money via targeting ATM systems, card processing, payment systems and SWIFT systems. Cobalt Group has mainly targeted banks in Eastern Europe, Central Asia, and Southeast Asia. One of the alleged leaders was arrested in Spain in early 2018, but the group still appears to be active. The group has been known to target organizations in order to use their access to then compromise additional victims.(Citation: Talos Cobalt Group July 2018)(Citation: PTSecurity Cobalt Group Aug 2017)(Citation: PTSecurity Cobalt Dec 2016)(Citation: Group IB Cobalt Aug 2017)(Citation: Proofpoint Cobalt June 2017)(Citation: RiskIQ Cobalt Nov 2017)(Citation: RiskIQ Cobalt Jan 2018) Reporting indicates there may be links between Cobalt Group and both the malware Carbanak and the group Carbanak.(Citation: Europol Cobalt Mar 2018)
Executive Summary
The Cobalt Group is a prominent cyber threat actor targeting financial institutions globally since at least 2016. Known for sophisticated attacks on financial systems, including ATM networks and SWIFT systems, the group primarily operates in Eastern Europe, Central Asia, and Southeast Asia despite leadership changes.
Goals & Targeting
The group targets financial institutions for monetary gain, focusing on regions with less robust cybersecurity measures. Their primary objectives include infiltrating banking systems to steal sensitive financial data and facilitate unauthorized transactions, leveraging their access to compromise additional victims.
Enhanced Description
Cobalt Group, also known as GOLD KINGSWOOD or Magecart Group 4, is a financially motivated cybercriminal group focusing on financial institutions. They employ advanced tactics to compromise ATM systems, card processing, and SWIFT networks. Originating from Eastern Europe and Central Asia, they have expanded their reach globally, including targeting banks in Southeast Asia. Notably linked to the Carbanak malware, Cobalt Group has proven resilient, continuing operations post-arrests of key members.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The Cobalt Group is known for prolonged campaigns targeting financial sectors, using techniques like supply chain compromise and persistence mechanisms. Notable operations include attacks on banks in Eastern Europe and Southeast Asia.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence is high in Cobalt Group's activities, though there are inconsistencies regarding their primary motivation (espionage vs. financial gain).
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
34
Techniques
4
Tools
0
Campaigns
0
IOCs
0
Observed Data
9
Tactics