Positive Technologies - learn and secure : Cobalt strikes back: an evolving multinational threat to finance
ID: d4eed14a-5058-4a1f-89a8-cfa3c7199d65
STIX ID: report--d4eed14a-5058-4a1f-89a8-cfa3c7199d65
Threat Score
78/100
Uploaded: 2026-08-14
Published Date: 2017-08-03
Last Modified Date: 2017-08-03
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Positive Technologies' 2017 analysis of the Cobalt group describes an evolving multinational financially motivated campaign that uses spear-phishing, compromised partner infrastructure, and Office-document exploits (notably CVE-2017-0199) to deliver Beacon/Cobalt Strike droppers and steal cash (including ATM cash-outs); the report details file types, delivery waves, infrastructure (phishing domains, alexusMailer), geographic targeting, and recommended defensive measures.
