Cobalt__2017__Cobalt-2017-eng.pdf
ID: 19b82a1e-d370-439e-8280-fa2d643c9c3c
STIX ID: report--19b82a1e-d370-439e-8280-fa2d643c9c3c
Threat Score
80/100
Uploaded: 2026-08-14
Published Date: 2017-08-16
Last Modified Date: 2017-08-16
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Positive Technologies report analyzes the 2017 Cobalt campaign: a multinational, financially motivated threat actor that used partner-compromises and supply‑chain phishing to deliver exploit-based Microsoft Office documents (including CVE-2017-0199), password-protected archives, LNK droppers and Beacon (Cobalt Strike) implants to compromise banks and financial organizations globally, describing their targets, timelines, infrastructure, filetypes, and recommended defenses.
