CobInt is a modular Windows malware family associated primarily with the financially motivated threat actor Cobalt Gang, also known as Cobalt Group, and has also been observed in later Russia-targeting intrusion clusters including Twelve, Head Mare, Crypt Ghouls, and activity linked to ExCobalt. It has been described both as a modular downloader and as a self-developed backdoor, reflecting its role as an initial foothold that can also provide remote access and selectively stage additional payloads.
CobInt has been delivered in phishing campaigns that impersonated financial institutions, payment brands, and security vendors. Observed lures used malicious Word documents, direct-download links, and exploit documents leveraging vulnerabilities including CVE-2017-8570, CVE-2017-11882, CVE-2018-0802, and CVE-2018-8174. In later intrusions, CobInt was also launched through script-based loaders, including VBScript and PowerShell chains, and was used after exploitation of internet-facing services such as Microsoft Exchange.
Technically, CobInt is a multi-stage malware framework written in C. Reported variants use a small first-stage downloader, a main component that polls command-and-control infrastructure over HTTPS, and optional third-stage modules delivered as shellcode and executed as DLLs. The malware employs API hashing, XOR-based obfuscation, encrypted configuration data, dynamically generated request paths, and disguised command-and-control responses to hinder analysis and detection. Supported commands include loading and executing modules, invoking module-registered functions, changing polling behavior, and halting beaconing.
Observed CobInt functionality includes host reconnaissance such as collecting running process information and capturing screenshots. Some reporting also attributes desktop video streaming capability to the malware. Operators appear to use this intelligence to decide whether a compromised system merits further exploitation. On systems judged valuable, CobInt has been used to download and launch follow-on tooling including Cobalt Strike. In multiple later campaigns, CobInt served as a remote-access component on high-value systems such as domain controllers.
CobInt has been used in financially motivated operations against banks and other financial-sector organizations and has also appeared in attacks on Russian government and commercial entities across sectors including energy, mining, finance, retail, manufacturing, and public administration. Its reuse across several clusters suggests either shared tooling, operational collaboration, or transfer of malware between related actors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A Microsoft Word attachment (sepa rules.doc) -- a ThreadKit exploit document that would exploit CVE-2017-8570, CVE-2017-11882, or CVE-2018-0802 -- to execute the embedded CobInt Stage 1 payload. | Group-IB named this malware “CobInt” and released a report on its use by Cobalt Gang in May. ... In this post, we describe recent activity that we have observed and analyze the multi-stage CobInt malware in detail.
A Microsoft Word attachment (sepa rules.doc) -- a ThreadKit exploit document that would exploit CVE-2017-8570, CVE-2017-11882, or CVE-2018-0802 -- to execute the embedded CobInt Stage 1 payload. | Group-IB named this malware “CobInt” and released a report on its use by Cobalt Gang in May. ... In this post, we describe recent activity that we have observed and analyze the multi-stage CobInt malware in detail.
A Microsoft Word attachment (sepa rules.doc) -- a ThreadKit exploit document that would exploit CVE-2017-8570, CVE-2017-11882, or CVE-2018-0802 -- to execute the embedded CobInt Stage 1 payload. | Group-IB named this malware “CobInt” and released a report on its use by Cobalt Gang in May. ... In this post, we describe recent activity that we have observed and analyze the multi-stage CobInt malware in detail.
The messages contained a Microsoft Word attachment that used a relationship object to download an external VBscript file containing an exploit for CVE-2018-8174 leading to the execution of CobInt stage 1. | Group-IB named this malware “CobInt” and released a report on its use by Cobalt Gang in May. ... In this post, we describe recent activity that we have observed and analyze the multi-stage CobInt malware in detail.
In one incident, they exploited the Microsoft Exchange server vulnerability CVE-2021-26855 (ProxyLogon). Although patched in 2021, this vulnerability is still exploitable due to organizations using outdated operating systems and software. The attackers used ProxyLogon to execute a command to download and launch CobInt on the server. | For instance, they used the CobInt backdoor for remote access to domain controllers, previously observed only in Twelve’s attacks on Russian companies.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
L’arsenal de Cobalt Gang se compose de codes malveillants qui lui sont spécifiques (Kayslice, CobInt).
Group-IB named this malware “CobInt” and released a report on its use by Cobalt Gang in May. ... In this post, we describe recent activity that we have observed and analyze the multi-stage CobInt malware in detail.
For instance, they used the CobInt backdoor for remote access to domain controllers, previously observed only in Twelve’s attacks on Russian companies.
For instance, they used the CobInt backdoor for remote access to domain controllers, previously observed only in Twelve’s attacks on Russian companies.
In one Crypt Ghouls attack, we discovered a malicious CobInt backdoor loader.
In one Crypt Ghouls attack, we discovered a malicious CobInt backdoor loader.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
...threat actors leveraging a contractor's login credentials to connect to the internal systems via VPN... weaponizing trusted relationships.
"...Outlook Web Access credentials by injecting malicious code into the login page..."
The attackers also exploited software vulnerabilities... In one incident, they exploited the Microsoft Exchange server vulnerability CVE-2021-26855 (ProxyLogon)... The attackers used ProxyLogon to execute a command to download and launch CobInt on the server.
This code, in turn, communicates with a C2 server to load the CobInt backdoor into memory.
In some cases, URLs linking directly to the CobInt downloader.
The decrypted data contains a DLL, which is CobInt’s main component. Stage 1 finishes by loading and executing the DLL.
Its functionality is disguised by the use of Windows API function hashing... The C&C host and URI are stored as encrypted strings... The response data is encrypted using three layers... The response is meant to look like an HTML file... but, in fact, contains encrypted data.
The decrypted data contains a DLL, which is CobInt’s main component. Stage 1 finishes by loading and executing the DLL.
At the time of publication we have observed two modules being sent from a C&C server, whose function was to: ... Send a list of running process names to the C&C
54 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor/loader delivered via the VBScript Intellpui.vbs, which executes obfuscated PowerShell to communicate with a C2 server and load the CobInt backdoor into memory.
Backdoor used by ExCobalt; associated activity includes credential theft from Telegram and Outlook Web Access via malicious code injection into the login page.
A self-developed modular backdoor used by the Cobalt group for reconnaissance on compromised machines, including collecting host intelligence and streaming desktop video, then downloading and launching a Cobalt Strike stager if the victim is deemed valuable.
Backdoor/loader used to execute obfuscated PowerShell and load additional malware into memory (fileless/in-memory execution), reducing on-disk artifacts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.