Threat group.View on attack.mitre.org
Cobalt Group is a financially motivated threat group that has primarily targeted financial institutions since at least 2016. The group has conducted intrusions to steal money via targeting ATM systems, card processing, payment systems and SWIFT systems. Cobalt Group has mainly targeted banks in Eastern Europe, Central Asia, and Southeast Asia. One of the alleged leaders was arrested in Spain in early 2018, but the group still appears to be active. The group has been known to target organizations in order to use their access to then compromise additional victims. Reporting indicates there may be links between Cobalt Group and both the malware Carbanak and the group Carbanak.
| Technique | Procedure example |
|---|---|
| T1021.001 Remote Desktop Protocol |
Cobalt Group has used Remote Desktop Protocol to conduct lateral movement. |
| T1027.010 Command Obfuscation |
Cobalt Group obfuscated several scriptlets and code used on the victim’s machine, including through use of XOR and RC4. |
| T1037.001 Logon Script (Windows) |
Cobalt Group has added persistence by registering the file name for the next stage malware under |
| T1046 Network Service Discovery |
Cobalt Group leveraged an open-source tool called SoftPerfect Network Scanner to perform network scanning. |
| T1053.005 Scheduled Task |
Cobalt Group has created Windows tasks to establish persistence. |
| T1055 Process Injection |
Cobalt Group has injected code into trusted processes. |
| T1059.001 PowerShell |
Cobalt Group has used powershell.exe to download and execute scripts. |
| T1059.003 Windows Command Shell |
Cobalt Group has used a JavaScript backdoor that is capable of launching cmd.exe to execute shell commands. The group has used an exploit toolkit known as Threadkit that launches .bat files. |
| T1059.005 Visual Basic |
Cobalt Group has sent Word OLE compound documents with malicious obfuscated VBA macros that will run upon user execution. |
| T1059.007 JavaScript |
Cobalt Group has executed JavaScript scriptlets on the victim's machine. |
| T1068 Exploitation for Privilege Escalation |
Cobalt Group has used exploits to increase their levels of rights and privileges. |
| T1070.004 File Deletion |
Cobalt Group deleted the DLL dropper from the victim’s machine to cover their tracks. |
| T1071.001 Web Protocols |
Cobalt Group has used HTTPS for C2. |
| T1071.004 DNS |
Cobalt Group has used DNS tunneling for C2. |
| T1105 Ingress Tool Transfer |
Cobalt Group has used public sites such as github.com and sendspace.com to upload files and then download them to victim computers. The group's JavaScript backdoor is also capable of downloading files. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.