Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors COBALT KATANA

Also known as: Hive0081 (IBM), SectorD01 (NHSC), xHunt campaign (Palo Alto), Hunter Serpens

Description

COBALT KATANA has been active since at least March 2018, and it focuses many of its operations on organizations based in or associated with Kuwait. The group has targeted government, logistics, and shipping organizations. The threat actors gain initial access to targets using DNS hijacking, strategic web compromise with SMB forced authentication, and password brute force attacks. COBALT KATANA operates a custom platform referred to as the Sakabota Framework, also referred to as Sakabota Core, with a complimentary set of modular backdoors and accessory tools including Gon, Hisoka, Hisoka Netero, Killua, Diezen, and Eye. The group has implemented DNS tunnelling in its malware and malicious scripts and also operates the HyphenShell web shell to strengthen post-intrusion access. CTU researchers assess with moderate confidence that COBALT KATANA operates on behalf of Iran, and elements of its operations such as overlapping infrastructure, use of DNS hijacking, implementation of DNS-based C2 channels in malware and web shell security mechanisms suggest connections to COBALT GYPSY and COBALT EDGEWATER.

AI Analysis

· 1 week ago

Executive Summary

COBALT KATANA is a threat actor active since at least March 2018, primarily targeting organizations in Kuwait, including government, logistics, and shipping sectors. The group employs advanced techniques such as DNS hijacking, SMB-based attacks, and custom malware frameworks. CTU researchers link the actor to Iran, citing operational overlaps with other Iranian-aligned groups.

Goals & Targeting

COBALT KATANA's targeting of Kuwaiti organizations likely reflects geopolitical interests aligned with Iran, aiming to gather intelligence, disrupt critical infrastructure, or undermine regional stability. The focus on government and logistics sectors suggests intent to infiltrate state systems or interfere with transportation networks, which could be leveraged for espionage, sabotage, or influence operations. The group's use of advanced tools and C2 methods indicates a strategic objective to maintain long-term access and avoid detection, aligning with state-sponsored cyber operations.

Enhanced Description

COBALT KATANA has been actively conducting operations since 2018, focusing on organizations in Kuwait and those with ties to the region. The group targets government, logistics, and shipping entities, leveraging sophisticated methods such as DNS hijacking, strategic web compromises via SMB forced authentication, and password brute-force attacks. A key component of their operations is the Sakabota Framework, a custom platform that includes modular backdoors and tools like Gon, Hisoka, Hisoka Netero, Killua, Diezen, and Eye. The group also utilizes DNS tunnelling for command-and-control (C2) communications and deploys the HyphenShell web shell to maintain persistent access. Intelligence suggests potential links to Iran, with operational techniques overlapping with other Iranian-aligned threat groups like COBALT GYPSY and COBALT EDGEWATER. These connections are based on shared infrastructure, DNS-based C2 mechanisms, and similar strategic web compromise tactics.

Key Capabilities

  • DNS hijacking for initial access
  • SMB forced authentication exploitation
  • Password brute-force attacks
  • Deployment of the Sakabota Framework (custom malware platform)
  • Use of modular backdoors (e.g., Hisoka, Killua)
  • DNS tunnelling for C2 communication
  • Implementation of the HyphenShell web shell for persistence
  • Strategic web compromise techniques

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Reconnaissance
Lateral Movement

ATT&CK Techniques

T1566.001 - DNS Tunneling
T1137.001 - SMB Execution
T1110.001 - Brute Force
T1071.006 - DNS for C2
T1210 - Web Shell
T1078.003 - Network Services
T1059.003 - Command-Line Interface

Software / Tooling

Sakabota Framework
Sakabota Core
Gon
Hisoka
Hisoka Netero
Killua
Diezen
Eye
HyphenShell

Campaigns & Victims

COBALT KATANA's campaigns are characterized by a focus on Kuwaiti targets, with operations involving DNS manipulation, SMB exploitation, and custom malware deployment. The group's tactics suggest a preference for stealthy, long-term access rather than rapid disruption. Campaigns often leverage overlapping infrastructure with other Iranian-aligned groups like COBALT GYPSY and COBALT EDGEWATER, indicating possible coordination or shared operational frameworks. Notable past operations include strategic web compromises and the use of modular backdoors to maintain access across multiple victim environments.

IOC Patterns

  • DNS hijacking for C2 redirection
  • SMB-based forced authentication exploitation
  • Brute-force attacks targeting weak credentials
  • Deployment of custom web shells (e.g., HyphenShell)
  • DNS tunnelling for data exfiltration
  • Staging infrastructure on bulletproof hosting services

Recommended Actions

  • Implement DNS monitoring and anomaly detection to identify hijacking attempts
  • Enforce multi-factor authentication (MFA) to mitigate brute-force risks
  • Deploy endpoint detection and response (EDR) solutions to detect Sakabota Framework activity
  • Segment networks to limit lateral movement post-compromise
  • Conduct regular vulnerability assessments for SMB and web application interfaces
  • Monitor for DNS tunnelling and irregular C2 traffic patterns
  • Incorporate threat intelligence feeds focusing on Iranian-linked groups and Kuwaiti targets

Suggested Tags

APT
espionage
Iran-linked
government-sector
logistics-sector
Kuwait

Confidence Assessment

Confidence in the attribution of COBALT KATANA to Iran is moderate, based on overlapping infrastructure and techniques with known Iranian-aligned groups. However, gaps remain in fully understanding the actor's command structure, full TTPs, and the extent of unreported campaigns. The lack of confirmed public samples or detailed victim logs limits further analysis.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
Backdoor / C2
Government Targeting
APT
espionage
Iran-linked
government-sector
logistics-sector
Kuwait

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.