Cobalt Group

Description

Cobalt Group is a financially motivated threat group that has primarily targeted financial institutions. The group has conducted intrusions to steal money via targeting ATM systems, card processing, payment systems and SWIFT systems. Cobalt Group has mainly targeted banks in Eastern Europe, Central Asia, and Southeast Asia. The group has been known to target organizations in order to use their access to then compromise additional victims. Reporting indicates there may be links between Cobalt Group and both the malware Carbanak and the group Carbanak, Anunak.

Names

NameName-Giver
Cobalt GroupGroup-IB
Cobalt GangPalo Alto
Cobalt SpiderCrowdStrike
Gold KingswoodSecureWorks
ATK 67Thales
TAG-CR3Recorded Future
Mule LibraPalo Alto

Country

Motivation

  • Financial crime

First Seen

2016

Observed Sectors

Observed Countries

Tools

Operations

Counter Operations

Information

Mitre Attack

Playbook

Other Information

Uuid

d8339e9a-c946-4304-aac4-722d8652d273

Last Card Change

2024-03-10