Cobalt Group is a financially motivated cybercrime threat actor known for targeted spearphishing campaigns against organizations, particularly in the financial sector. The group is also tracked under aliases including Cobalt, Cobalt Gang, Cobalt Spider, and Gold Kingswood. It has been associated with the operational use and abuse of Cobalt Strike and has weaponized Microsoft Office exploits, including CVE-2017-11882, to gain execution on victim systems. The group commonly relies on email-based initial access, sending spearphishing messages with malicious attachments such as RTF, Office documents, archives, and macro-enabled files that require user interaction. Observed execution chains include malicious VBA macros, JavaScript or JScript scriptlets, PowerShell downloaders, and use of regsvr32 to launch scripts. Post-compromise activity includes command execution through the Windows shell, staged payload retrieval from public file-hosting or code-sharing services, and use of HTTPS for command-and-control communications. Cobalt Group has demonstrated persistence through Windows Scheduled Tasks, Registry Run keys, and Startup-folder-based mechanisms, including PowerShell-based launchers used to retrieve follow-on tooling. The group has also shown privilege-escalation capability through User Account Control bypass and has performed security software discovery by collecting information on defensive products installed on victim machines. Defense-evasion behavior includes deletion of droppers and other artifacts to reduce forensic visibility. The actor’s tradecraft reflects a multi-stage intrusion model centered on phishing-led compromise, script-based execution, persistence establishment, and post-exploitation control of infected systems. Available evidence in this dataset supports characterization as a cybercriminal intrusion set rather than a state-sponsored espionage actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
30 malware families attributed to this actor across reporting.
25 additional families tracked in Mallory.
9 CVEs this actor has used in observed campaigns. 9 of them exploited in the wild.
A Microsoft Word attachment (sepa rules.doc) -- a ThreadKit exploit document that would exploit CVE-2017-8570, CVE-2017-11882, or CVE-2018-0802 -- to execute the embedded CobInt Stage 1 payload.
After the latest update, MWI is now using CVE-2017-0199 to launch an HTML Application (HTA) used for both information collection and payload execution.
A Microsoft Word attachment (sepa rules.doc) -- a ThreadKit exploit document that would exploit CVE-2017-8570, CVE-2017-11882, or CVE-2018-0802 -- to execute the embedded CobInt Stage 1 payload.
Giagone, R., Bermejo, L., and Yarochkin, F. (2017, November 20). Cobalt Strikes Again: Spam Runs Use Macros and CVE-2017-8759 Exploit Against Russian Banks.
The messages contained a Microsoft Word attachment that used a relationship object to download an external VBscript file containing an exploit for CVE-2018-8174 leading to the execution of CobInt stage 1.
4 more CVEs tied to this actor tracked in Mallory.
146 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated with the generic installation exploitation analytic, but no campaign-specific activity is described in this reference.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Listed among detected threat actors/TTP references, but not substantively discussed in the report summary.
Mentioned as another historical Golden Chickens MaaS customer in attribution discussion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.