logo

Cobalt__2017__Cobalt-2017-eng.pdf

ID: 19b82a1e-d370-439e-8280-fa2d643c9c3c

STIX ID: report--19b82a1e-d370-439e-8280-fa2d643c9c3c

Threat Score

80/100

Uploaded: 2026-08-14

Published Date: 2017-08-16

Last Modified Date: 2017-08-16

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Positive Technologies report analyzes the 2017 Cobalt campaign: a multinational, financially motivated threat actor that used partner-compromises and supply‑chain phishing to deliver exploit-based Microsoft Office documents (including CVE-2017-0199), password-protected archives, LNK droppers and Beacon (Cobalt Strike) implants to compromise banks and financial organizations globally, describing their targets, timelines, infrastructure, filetypes, and recommended defenses.