ATT&CKReferencesTalos Cobalt Group July 2018

Talos Cobalt Group July 2018

Svajcer, V. (2018, July 31). Multiple Cobalt Personality Disorder. Retrieved September 5, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples25

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareMore_eggs

More_eggs has the capability to gather the IP address from the victim's machine.

T1027.010
Command Obfuscation
GroupCobalt Group

Cobalt Group obfuscated several scriptlets and code used on the victim’s machine, including through use of XOR and RC4.

T1033
System Owner/User Discovery
MalwareMore_eggs

More_eggs has the capability to gather the username from the victim's machine.

T1059.001
PowerShell
GroupCobalt Group

Cobalt Group has used powershell.exe to download and execute scripts.

T1059.003
Windows Command Shell
GroupCobalt Group

Cobalt Group has used a JavaScript backdoor that is capable of launching cmd.exe to execute shell commands. The group has used an exploit toolkit known as Threadkit that launches .bat files.

T1059.005
Visual Basic
GroupCobalt Group

Cobalt Group has sent Word OLE compound documents with malicious obfuscated VBA macros that will run upon user execution.

T1059.007
JavaScript
GroupCobalt Group

Cobalt Group has executed JavaScript scriptlets on the victim's machine.

T1070.004
File Deletion
GroupCobalt Group

Cobalt Group deleted the DLL dropper from the victim’s machine to cover their tracks.

T1070.004
File Deletion
MalwareMore_eggs

More_eggs can remove itself from a system.

T1071.001
Web Protocols
MalwareMore_eggs

More_eggs uses HTTPS for C2.

T1071.001
Web Protocols
GroupCobalt Group

Cobalt Group has used HTTPS for C2.

T1071.004
DNS
GroupCobalt Group

Cobalt Group has used DNS tunneling for C2.

T1082
System Information Discovery
MalwareMore_eggs

More_eggs has the capability to gather the OS version and computer name.

T1105
Ingress Tool Transfer
MalwareMore_eggs

More_eggs can download and launch additional payloads.

T1203
Exploitation for Client Execution
GroupCobalt Group

Cobalt Group had exploited multiple vulnerabilities for execution, including Microsoft’s Equation Editor (CVE-2017-11882), an Internet Explorer vulnerability (CVE-2018-8174), CVE-2017-8570, CVE-2017-0199, and CVE-2017-8759.

T1204.001
Malicious Link
GroupCobalt Group

Cobalt Group has sent emails containing malicious links that require users to execute a file or macro to infect the victim machine.

T1204.002
Malicious File
GroupCobalt Group

Cobalt Group has sent emails containing malicious attachments that require users to execute a file or macro to infect the victim machine.

T1218.003
CMSTP
GroupCobalt Group

Cobalt Group has used the command cmstp.exe /s /ns C:\Users\ADMINI~W\AppData\Local\Temp\XKNqbpzl.txt to bypass AppLocker and launch a malicious script.

T1218.010
Regsvr32
GroupCobalt Group

Cobalt Group has used regsvr32.exe to execute scripts.

T1220
XSL Script Processing
GroupCobalt Group

Cobalt Group used msxsl.exe to bypass AppLocker and to invoke Jscript code from an XSL file.

T1518.001
Security Software Discovery
MalwareMore_eggs

More_eggs can obtain information on installed anti-malware programs.

T1559.002
Dynamic Data Exchange
GroupCobalt Group

Cobalt Group has sent malicious Word OLE compound documents to victims.

T1566.001
Spearphishing Attachment
GroupCobalt Group

Cobalt Group has sent spearphishing emails with various attachment types to corporate and personal email accounts of victim organizations. Attachment types have included .rtf, .doc, .xls, archives containing LNK files, and password protected archives containing .exe and .scr executables.

T1566.002
Spearphishing Link
GroupCobalt Group

Cobalt Group has sent emails with URLs pointing to malicious documents.

T1572
Protocol Tunneling
GroupCobalt Group

Cobalt Group has used the Plink utility to create SSH tunnels.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.