Also known as: Hive0081 (IBM), SectorD01 (NHSC), xHunt campaign (Palo Alto), Hunter Serpens
COBALT KATANA has been active since at least March 2018, and it focuses many of its operations on organizations based in or associated with Kuwait. The group has targeted government, logistics, and shipping organizations. The threat actors gain initial access to targets using DNS hijacking, strategic web compromise with SMB forced authentication, and password brute force attacks. COBALT KATANA operates a custom platform referred to as the Sakabota Framework, also referred to as Sakabota Core, with a complimentary set of modular backdoors and accessory tools including Gon, Hisoka, Hisoka Netero, Killua, Diezen, and Eye. The group has implemented DNS tunnelling in its malware and malicious scripts and also operates the HyphenShell web shell to strengthen post-intrusion access. CTU researchers assess with moderate confidence that COBALT KATANA operates on behalf of Iran, and elements of its operations such as overlapping infrastructure, use of DNS hijacking, implementation of DNS-based C2 channels in malware and web shell security mechanisms suggest connections to COBALT GYPSY and COBALT EDGEWATER.
Executive Summary
COBALT KATANA is a threat actor active since at least March 2018, primarily targeting organizations in Kuwait, including government, logistics, and shipping sectors. The group employs advanced techniques such as DNS hijacking, SMB-based attacks, and custom malware frameworks. CTU researchers link the actor to Iran, citing operational overlaps with other Iranian-aligned groups.
Goals & Targeting
COBALT KATANA's targeting of Kuwaiti organizations likely reflects geopolitical interests aligned with Iran, aiming to gather intelligence, disrupt critical infrastructure, or undermine regional stability. The focus on government and logistics sectors suggests intent to infiltrate state systems or interfere with transportation networks, which could be leveraged for espionage, sabotage, or influence operations. The group's use of advanced tools and C2 methods indicates a strategic objective to maintain long-term access and avoid detection, aligning with state-sponsored cyber operations.
Enhanced Description
COBALT KATANA has been actively conducting operations since 2018, focusing on organizations in Kuwait and those with ties to the region. The group targets government, logistics, and shipping entities, leveraging sophisticated methods such as DNS hijacking, strategic web compromises via SMB forced authentication, and password brute-force attacks. A key component of their operations is the Sakabota Framework, a custom platform that includes modular backdoors and tools like Gon, Hisoka, Hisoka Netero, Killua, Diezen, and Eye. The group also utilizes DNS tunnelling for command-and-control (C2) communications and deploys the HyphenShell web shell to maintain persistent access. Intelligence suggests potential links to Iran, with operational techniques overlapping with other Iranian-aligned threat groups like COBALT GYPSY and COBALT EDGEWATER. These connections are based on shared infrastructure, DNS-based C2 mechanisms, and similar strategic web compromise tactics.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
COBALT KATANA's campaigns are characterized by a focus on Kuwaiti targets, with operations involving DNS manipulation, SMB exploitation, and custom malware deployment. The group's tactics suggest a preference for stealthy, long-term access rather than rapid disruption. Campaigns often leverage overlapping infrastructure with other Iranian-aligned groups like COBALT GYPSY and COBALT EDGEWATER, indicating possible coordination or shared operational frameworks. Notable past operations include strategic web compromises and the use of modular backdoors to maintain access across multiple victim environments.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the attribution of COBALT KATANA to Iran is moderate, based on overlapping infrastructure and techniques with known Iranian-aligned groups. However, gaps remain in fully understanding the actor's command structure, full TTPs, and the extent of unreported campaigns. The lack of confirmed public samples or detailed victim logs limits further analysis.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics