ATT&CKReferencesPTSecurity Cobalt Dec 2016

PTSecurity Cobalt Dec 2016

Positive Technologies. (2016, December 16). Cobalt Snatch. Retrieved October 9, 2018.

Open the source

Techniques1

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1046
Network Service Discovery
GroupCobalt Group

Cobalt Group leveraged an open-source tool called SoftPerfect Network Scanner to perform network scanning.

T1059.001
PowerShell
GroupCobalt Group

Cobalt Group has used powershell.exe to download and execute scripts.

T1071.001
Web Protocols
GroupCobalt Group

Cobalt Group has used HTTPS for C2.

T1071.004
DNS
GroupCobalt Group

Cobalt Group has used DNS tunneling for C2.

T1105
Ingress Tool Transfer
GroupCobalt Group

Cobalt Group has used public sites such as github.com and sendspace.com to upload files and then download them to victim computers. The group's JavaScript backdoor is also capable of downloading files.

T1203
Exploitation for Client Execution
GroupCobalt Group

Cobalt Group had exploited multiple vulnerabilities for execution, including Microsoft’s Equation Editor (CVE-2017-11882), an Internet Explorer vulnerability (CVE-2018-8174), CVE-2017-8570, CVE-2017-0199, and CVE-2017-8759.

T1219
Remote Access Tools
GroupCobalt Group

Cobalt Group used the Ammyy Admin tool as well as TeamViewer for remote access, including to preserve remote access if a Cobalt Strike module was lost.

T1566.001
Spearphishing Attachment
GroupCobalt Group

Cobalt Group has sent spearphishing emails with various attachment types to corporate and personal email accounts of victim organizations. Attachment types have included .rtf, .doc, .xls, archives containing LNK files, and password protected archives containing .exe and .scr executables.

T1572
Protocol Tunneling
GroupCobalt Group

Cobalt Group has used the Plink utility to create SSH tunnels.

T1588.002
Tool
GroupCobalt Group

Cobalt Group has obtained and used a variety of tools including Mimikatz, PsExec, Cobalt Strike, and SDelete.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.