news.mlab.sh
Threat intelligence
Threat actor

Cobalt Group

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
Russia
First seen
2016-01-01 00:00:00
Motivation
Financial crime
Targeted sectors
Financial, High-Tech, Media, Retail
TLP
WHITE

Cobalt Group is a financially motivated threat group that has primarily targeted financial institutions. The group has conducted intrusions to steal money via targeting ATM systems, card processing, payment systems and SWIFT systems. Cobalt Group has mainly targeted banks in Eastern Europe, Central Asia, and Southeast Asia. The group has been known to target organizations in order to use their access to then compromise additional victims. Reporting indicates there may be links between Cobalt Group and both the malware Carbanak and the group Carbanak, Anunak.

Also known as

ATK 67Cobalt GangCobalt GroupCobalt SpiderG0080Gold KingswoodMule LibraTAG-CR3

Vulnerabilities exploited

Tooling and malware

Cobalt StrikeMore_eggsSpicyOmeletteMimikatzPsExecSDelete

MITRE ATT&CK techniques

T1105 Ingress Tool TransferT1219 Remote Access ToolsT1572 Protocol TunnelingT1046 Network Service DiscoveryT1203 Exploitation for Client ExecutionT1068 Exploitation for Privilege EscalationT1055 Process InjectionT1220 XSL Script Processing

Coverage 2

threat-intel

The Alert Firehose Finally Meets Its Match

This article discusses the evolution of Network Detection and Response (NDR) systems, particularly with the integration of agentic AI. It highlights how early NDR deployments suffered from a "noisy" alert firehose due to…

The Hacker News · May 25, 2026 Medium