ATT&CKReferencesPTSecurity Cobalt Group Aug 2017

PTSecurity Cobalt Group Aug 2017

Positive Technologies. (2017, August 16). Cobalt Strikes Back: An Evolving Multinational Threat to Finance. Retrieved September 5, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1046
Network Service Discovery
GroupCobalt Group

Cobalt Group leveraged an open-source tool called SoftPerfect Network Scanner to perform network scanning.

T1059.001
PowerShell
GroupCobalt Group

Cobalt Group has used powershell.exe to download and execute scripts.

T1059.003
Windows Command Shell
GroupCobalt Group

Cobalt Group has used a JavaScript backdoor that is capable of launching cmd.exe to execute shell commands. The group has used an exploit toolkit known as Threadkit that launches .bat files.

T1059.005
Visual Basic
GroupCobalt Group

Cobalt Group has sent Word OLE compound documents with malicious obfuscated VBA macros that will run upon user execution.

T1059.007
JavaScript
GroupCobalt Group

Cobalt Group has executed JavaScript scriptlets on the victim's machine.

T1105
Ingress Tool Transfer
GroupCobalt Group

Cobalt Group has used public sites such as github.com and sendspace.com to upload files and then download them to victim computers. The group's JavaScript backdoor is also capable of downloading files.

T1203
Exploitation for Client Execution
GroupCobalt Group

Cobalt Group had exploited multiple vulnerabilities for execution, including Microsoft’s Equation Editor (CVE-2017-11882), an Internet Explorer vulnerability (CVE-2018-8174), CVE-2017-8570, CVE-2017-0199, and CVE-2017-8759.

T1219
Remote Access Tools
GroupCobalt Group

Cobalt Group used the Ammyy Admin tool as well as TeamViewer for remote access, including to preserve remote access if a Cobalt Strike module was lost.

T1566.001
Spearphishing Attachment
GroupCobalt Group

Cobalt Group has sent spearphishing emails with various attachment types to corporate and personal email accounts of victim organizations. Attachment types have included .rtf, .doc, .xls, archives containing LNK files, and password protected archives containing .exe and .scr executables.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.