logo

Positive Technologies - learn and secure : Cobalt strikes back: an evolving multinational threat to finance

ID: d4eed14a-5058-4a1f-89a8-cfa3c7199d65

STIX ID: report--d4eed14a-5058-4a1f-89a8-cfa3c7199d65

Threat Score

78/100

Uploaded: 2026-08-14

Published Date: 2017-08-03

Last Modified Date: 2017-08-03

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Positive Technologies' 2017 analysis of the Cobalt group describes an evolving multinational financially motivated campaign that uses spear-phishing, compromised partner infrastructure, and Office-document exploits (notably CVE-2017-0199) to deliver Beacon/Cobalt Strike droppers and steal cash (including ATM cash-outs); the report details file types, delivery waves, infrastructure (phishing domains, alexusMailer), geographic targeting, and recommended defensive measures.