Double the Infection, Double the Fun
ID: 31784cb9-5564-4b78-b652-85e40cd10229
STIX ID: report--31784cb9-5564-4b78-b652-85e40cd10229
Threat Score
78/100
Uploaded: 2026-08-14
Published Date: 2018-10-16
Last Modified Date: 2018-10-16
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ASERT reports an active Cobalt Group campaign targeting financial institutions (notably in Russia and Romania) using spear-phishing with dual malicious links: a weaponized Word macro that stages a regsvr32/cmstp-based infection chain dropping a JavaScript backdoor (“more_eggs”), and an executable masquerading as a JPEG tied to CobInt/COOLPANTS reconnaissance backdoors; the report includes TTPs, multiple C2 domains, and a detailed set of IOCs for detection and blocking.
