CobInt is a modular Windows backdoor and downloader associated with Cobalt Gang, which has used it since late 2017 in attacks against banks and financial organizations. It supports initial reconnaissance and selective deployment of additional payloads, including Cobalt Strike stagers. Subsequent use has been documented in operations involving ExCobalt, Crypt Ghouls, Twelve, and Head Mare, including attacks against Russian organizations and remote access to domain controllers.
Written in C, CobInt uses a multistage architecture comprising an initial downloader, a main DLL component, and dynamically retrieved modules. The main component polls command-and-control infrastructure over HTTPS and supports module execution, invocation of module-registered functions, changes to polling intervals, and cessation of polling. Observed modules collect running-process names and screenshots and transmit the results to operators. Payloads and plugins can be loaded directly into memory using reflective loading. API hashing, XOR encryption, custom encoding, encrypted strings, and command-and-control responses disguised as HTML hinder detection and analysis. Later deployment chains have used VBScript launchers and obfuscated PowerShell to load CobInt into memory.
Delivery methods include phishing emails impersonating financial institutions, payment services, and security vendors, with direct download links or malicious Word documents. Exploit-document campaigns have used ThreadKit and vulnerabilities including CVE-2017-8570, CVE-2017-11882, CVE-2018-0802, and CVE-2018-8174. CobInt has also been distributed through fake browser updates on a financial-institution impersonation website and through virtual hard disk containers requiring manual execution. In a later intrusion, exploitation of Microsoft Exchange vulnerability CVE-2021-26855 led to CobInt deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A Microsoft Word attachment (sepa rules.doc) -- a ThreadKit exploit document that would exploit CVE-2017-8570, CVE-2017-11882, or CVE-2018-0802 -- to execute the embedded CobInt Stage 1 payload. | Group-IB named this malware “CobInt” and released a report on its use by Cobalt Gang in May. ... In this post, we describe recent activity that we have observed and analyze the multi-stage CobInt malware in detail.
A Microsoft Word attachment (sepa rules.doc) -- a ThreadKit exploit document that would exploit CVE-2017-8570, CVE-2017-11882, or CVE-2018-0802 -- to execute the embedded CobInt Stage 1 payload. | Group-IB named this malware “CobInt” and released a report on its use by Cobalt Gang in May. ... In this post, we describe recent activity that we have observed and analyze the multi-stage CobInt malware in detail.
A Microsoft Word attachment (sepa rules.doc) -- a ThreadKit exploit document that would exploit CVE-2017-8570, CVE-2017-11882, or CVE-2018-0802 -- to execute the embedded CobInt Stage 1 payload. | Group-IB named this malware “CobInt” and released a report on its use by Cobalt Gang in May. ... In this post, we describe recent activity that we have observed and analyze the multi-stage CobInt malware in detail.
The messages contained a Microsoft Word attachment that used a relationship object to download an external VBscript file containing an exploit for CVE-2018-8174 leading to the execution of CobInt stage 1. | Group-IB named this malware “CobInt” and released a report on its use by Cobalt Gang in May. ... In this post, we describe recent activity that we have observed and analyze the multi-stage CobInt malware in detail.
In one incident, they exploited the Microsoft Exchange server vulnerability CVE-2021-26855 (ProxyLogon). Although patched in 2021, this vulnerability is still exploitable due to organizations using outdated operating systems and software. The attackers used ProxyLogon to execute a command to download and launch CobInt on the server. | For instance, they used the CobInt backdoor for remote access to domain controllers, previously observed only in Twelve’s attacks on Russian companies.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
One of Cobalt's hallmarks was the use of the CobInt tool, something ExCobalt began to use in 2022.
One of Cobalt's hallmarks was the use of the CobInt tool, something ExCobalt began to use in 2022.
Group-IB named this malware “CobInt” and released a report on its use by Cobalt Gang in May. ... In this post, we describe recent activity that we have observed and analyze the multi-stage CobInt malware in detail.
For instance, they used the CobInt backdoor for remote access to domain controllers, previously observed only in Twelve’s attacks on Russian companies.
For instance, they used the CobInt backdoor for remote access to domain controllers, previously observed only in Twelve’s attacks on Russian companies.
In one Crypt Ghouls attack, we discovered a malicious CobInt backdoor loader.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
...threat actors leveraging a contractor's login credentials to connect to the internal systems via VPN... weaponizing trusted relationships.
"...Outlook Web Access credentials by injecting malicious code into the login page..."
The attackers also exploited software vulnerabilities... In one incident, they exploited the Microsoft Exchange server vulnerability CVE-2021-26855 (ProxyLogon)... The attackers used ProxyLogon to execute a command to download and launch CobInt on the server.
This code, in turn, communicates with a C2 server to load the CobInt backdoor into memory.
In some cases, URLs linking directly to the CobInt downloader.
The messages contained a Microsoft Word attachment that used a relationship object to download an external VBscript file containing an exploit for CVE-2018-8174 leading to the execution of CobInt stage 1.
The decrypted data contains a DLL, which is CobInt’s main component. Stage 1 finishes by loading and executing the DLL.
“It has a built-in obfuscator for the hard-coded JavaScript backdoor and JavaScript loader”; “The payload is encoded using RC4 and Base91 and inserted in the script.”
The decrypted data contains a DLL, which is CobInt’s main component. Stage 1 finishes by loading and executing the DLL.
At the time of publication we have observed two modules being sent from a C&C server, whose function was to: ... Send a list of running process names to the C&C
87 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor/loader delivered via the VBScript Intellpui.vbs, which executes obfuscated PowerShell to communicate with a C2 server and load the CobInt backdoor into memory.
Backdoor used by ExCobalt; associated activity includes credential theft from Telegram and Outlook Web Access via malicious code injection into the login page.
A self-developed modular backdoor used by the Cobalt group for reconnaissance on compromised machines, including collecting host intelligence and streaming desktop video, then downloading and launching a Cobalt Strike stager if the victim is deemed valuable.
Named malware represented by three MainModule samples with associated hashes. The supplied content does not describe its behavior, delivery mechanism, or operational role.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.