Threat Actor Unknown origin
Cobalt
Also known as: Cobalt Group · Cobalt Gang · GOLD KINGSWOOD · COBALT SPIDER · G0080 · Mule Libra
A criminal group dubbed Cobalt is behind synchronized ATM heists that saw machines across Europe, CIS countries (including Russia), and Malaysia being raided simultaneously, in the span of a few hours. The group has been active since June 2016, and their latest attacks happened in July and August.
MITRE ATT&CK TTPs 16
T1003 T1005 T1021 T1040 T1056.001 T1059 T1059.001 T1070.004 T1071.001 T1074 T1082 T1083 T1110 T1123 T1203 T1566
OS Credential Dumping
Credential Access
Data from Local System
Collection
Remote Services
Lateral Movement
Network Sniffing
Credential Access
Keylogging
Collection
Command and Scripting Interpreter
Execution
PowerShell
Execution
File Deletion
Defense Evasion
Web Protocols
Command And Control
Data Staged
Collection
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Brute Force
Credential Access
Audio Capture
Collection
Exploitation for Client Execution
Execution
Phishing
Initial Access