ExCobalt is a cyberespionage-focused threat group targeting Russian organizations in metallurgy, mining, telecommunications, information technology, software development, and government. Its membership includes individuals active since at least 2016. Shedding Zmiy is an associated activity cluster, but is not established as an interchangeable alias. ExCobalt has used CobInt since 2022, sharing this tool with the Cobalt group. ExCobalt obtains initial access by exploiting known vulnerabilities in internet-facing corporate services and using credentials stolen from contractors to penetrate target networks. Its operations include credential harvesting, reconnaissance, privilege escalation, lateral movement, and data exfiltration. Credential-theft activity includes collecting Telegram credentials and message histories and injecting malicious code into Outlook Web Access login pages to capture authentication details. Its toolkit includes Mimikatz, ProcDump, SMBExec, Metasploit, web shells, remote-access utilities, and Linux privilege-escalation exploits. A principal implant is GoRed, a Go-based backdoor supporting encrypted command-and-control, reverse shells, network scanning, SOCKS proxying, reverse port forwarding, filesystem and credential monitoring, and collection of host, process, network, and file data. It supports service-based persistence and communication over WebSocket, QUIC, DNS, and ICMP. ExCobalt also conceals malicious processes and network connections through modified Linux system utilities and uses rootkit tooling. Its associated arsenal includes Babuk and LockBit lockers, although its dominant operational focus is espionage rather than an established ransomware-extortion business model.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
25 malware families attributed to this actor across reporting.
20 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
50 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Activity cluster whose members may be participating in overlapping campaigns targeting Russian organizations; associated here through Shedding Zmiy and shared tooling/infrastructure patterns.
Campaigns targeting Russian organizations using exploitation of known vulnerabilities and use of stolen credentials.
Targets Russian organizations; gains initial access by exploiting known vulnerabilities and using contractor-stolen credentials; conducts credential theft (Telegram/OWA) and uses a mix of backdoors, rootkits, and ransomware lockers.
Targets Russian organizations; gains initial access via exploitation of known vulnerabilities and use of contractor-stolen credentials; conducts credential theft (Telegram and OWA) and uses a mix of backdoors, rootkits, and ransomware lockers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.