logo

Double the Infection, Double the Fun

ID: 31784cb9-5564-4b78-b652-85e40cd10229

STIX ID: report--31784cb9-5564-4b78-b652-85e40cd10229

Threat Score

78/100

Uploaded: 2026-08-14

Published Date: 2018-10-16

Last Modified Date: 2018-10-16

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ASERT reports an active Cobalt Group campaign targeting financial institutions (notably in Russia and Romania) using spear-phishing with dual malicious links: a weaponized Word macro that stages a regsvr32/cmstp-based infection chain dropping a JavaScript backdoor (“more_eggs”), and an executable masquerading as a JPEG tied to CobInt/COOLPANTS reconnaissance backdoors; the report includes TTPs, multiple C2 domains, and a detailed set of IOCs for detection and blocking.