Cobalt Group
Also reported as Cobalt Gang, GOLD KINGSWOOD, Mule Libra, Cobalt Spider, Cobalt and 4 other names. Linked to Russia by one source.
Reports per quarter
Techniques seen in the last two years
- T1053.005 8 reports in ATT&CK
- T1059.003 7 reports in ATT&CK
- T1105 7 reports in ATT&CK
- T1204.002 7 reports in ATT&CK
- T1057 6 reports reports only
- T1059.001 6 reports in ATT&CK
- T1071.001 6 reports in ATT&CK
- T1082 6 reports reports only
- T1566.001 6 reports in ATT&CK
- T1041 5 reports reports only
Show all 278 techniques Show fewer
- T1005 4 reports reports only
- T1027 4 reports reports only
- T1033 4 reports reports only
- T1055.002 4 reports reports only
- T1140 4 reports reports only
- T1189 4 reports reports only
- T1482 4 reports reports only
- T1518.001 4 reports in ATT&CK
- T1566.002 4 reports in ATT&CK
- T1572 4 reports in ATT&CK
- T1574.001 4 reports reports only
- T1007 3 reports reports only
- T1016 3 reports reports only
- T1018 3 reports reports only
- T1036 3 reports reports only
- T1046 3 reports in ATT&CK
- T1047 3 reports reports only
- T1059 3 reports reports only
- T1059.005 3 reports in ATT&CK
- T1059.007 3 reports in ATT&CK
- T1068 3 reports in ATT&CK
- T1069.002 3 reports reports only
- T1070.004 3 reports in ATT&CK
- T1071 3 reports reports only
- T1083 3 reports reports only
- T1087.001 3 reports reports only
- T1087.002 3 reports reports only
- T1132.001 3 reports reports only
- T1136.001 3 reports reports only
- T1190 3 reports reports only
- T1219 3 reports in ATT&CK
- T1505.003 3 reports reports only
- T1547.001 3 reports in ATT&CK
- T1566 3 reports reports only
- T1570 3 reports reports only
- T1573.001 3 reports reports only
- T1583.003 3 reports reports only
- T1608.001 3 reports reports only
- T1003.001 2 reports reports only
- T1003.002 2 reports reports only
- T1008 2 reports reports only
- T1016.001 2 reports reports only
- T1021.001 2 reports in ATT&CK
- T1021.002 2 reports reports only
- T1027.009 2 reports reports only
- T1027.010 2 reports in ATT&CK
- T1036.005 2 reports reports only
- T1049 2 reports reports only
- T1055 2 reports in ATT&CK
- T1055.004 2 reports reports only
- T1056.001 2 reports reports only
- T1059.006 2 reports reports only
- T1069.001 2 reports reports only
- T1071.004 2 reports in ATT&CK
- T1078 2 reports reports only
- T1090 2 reports reports only
- T1090.001 2 reports reports only
- T1095 2 reports reports only
- T1098 2 reports reports only
- T1098.007 2 reports reports only
- T1104 2 reports reports only
- T1119 2 reports reports only
- T1124 2 reports reports only
- T1129 2 reports reports only
- T1133 2 reports reports only
- T1135 2 reports reports only
- T1136 2 reports reports only
- T1204 2 reports reports only
- T1204.001 2 reports in ATT&CK
- T1217 2 reports reports only
- T1485 2 reports reports only
- T1489 2 reports reports only
- T1496 2 reports reports only
- T1497.003 2 reports reports only
- T1505.004 2 reports reports only
- T1543.003 2 reports in ATT&CK
- T1546.015 2 reports reports only
- T1548 2 reports reports only
- T1555.003 2 reports reports only
- T1560 2 reports reports only
- T1560.001 2 reports reports only
- T1566.004 2 reports reports only
- T1567 2 reports reports only
- T1571 2 reports reports only
- T1583 2 reports reports only
- T1583.001 2 reports reports only
- T1583.004 2 reports reports only
- T1587.001 2 reports reports only
- T1590 2 reports reports only
- T1595 2 reports reports only
- T1595.002 2 reports reports only
- T1608 2 reports reports only
- T1608.002 2 reports reports only
- T1608.006 2 reports reports only
- T1620 2 reports reports only
- T1649 2 reports reports only
- T1657 2 reports reports only
- T1003 1 report reports only
- T1010 1 report reports only
- T1012 1 report reports only
- T1020 1 report reports only
- T1021 1 report reports only
- T1021.004 1 report reports only
- T1021.005 1 report reports only
- T1021.006 1 report reports only
- T1027.002 1 report reports only
- T1027.013 1 report reports only
- T1027.014 1 report reports only
- T1036.003 1 report reports only
- T1037 1 report reports only
- T1037.001 1 report in ATT&CK
- T1039 1 report reports only
- T1040 1 report reports only
- T1048 1 report reports only
- T1053 1 report reports only
- T1053.003 1 report reports only
- T1055.001 1 report reports only
- T1055.003 1 report reports only
- T1055.009 1 report reports only
- T1055.012 1 report reports only
- T1056 1 report reports only
- T1059.002 1 report reports only
- T1059.004 1 report reports only
- T1059.009 1 report reports only
- T1059.010 1 report reports only
- T1059.011 1 report reports only
- T1069 1 report reports only
- T1069.003 1 report reports only
- T1070 1 report reports only
- T1072 1 report reports only
- T1074 1 report reports only
- T1074.001 1 report reports only
- T1074.002 1 report reports only
- T1078.002 1 report reports only
- T1078.003 1 report reports only
- T1078.004 1 report reports only
- T1087 1 report reports only
- T1087.004 1 report reports only
- T1090.003 1 report reports only
- T1091 1 report reports only
- T1098.001 1 report reports only
- T1098.003 1 report reports only
- T1098.004 1 report reports only
- T1098.005 1 report reports only
- T1098.006 1 report reports only
- T1102 1 report reports only
- T1102.002 1 report reports only
- T1113 1 report reports only
- T1114 1 report reports only
- T1114.001 1 report reports only
- T1114.002 1 report reports only
- T1114.003 1 report reports only
- T1115 1 report reports only
- T1120 1 report reports only
- T1123 1 report reports only
- T1125 1 report reports only
- T1132 1 report reports only
- T1134 1 report reports only
- T1134.001 1 report reports only
- T1136.002 1 report reports only
- T1137 1 report reports only
- T1137.006 1 report reports only
- T1195 1 report reports only
- T1195.001 1 report reports only
- T1195.002 1 report in ATT&CK
- T1199 1 report reports only
- T1200 1 report reports only
- T1201 1 report reports only
- T1203 1 report in ATT&CK
- T1204.004 1 report reports only
- T1210 1 report reports only
- T1213 1 report reports only
- T1213.001 1 report reports only
- T1213.002 1 report reports only
- T1213.003 1 report reports only
- T1218.007 1 report reports only
- T1484 1 report reports only
- T1484.001 1 report reports only
- T1486 1 report reports only
- T1490 1 report reports only
- T1491 1 report reports only
- T1491.002 1 report reports only
- T1497 1 report reports only
- T1497.001 1 report reports only
- T1498 1 report reports only
- T1505 1 report reports only
- T1518 1 report reports only
- T1528 1 report reports only
- T1529 1 report reports only
- T1530 1 report reports only
- T1534 1 report reports only
- T1537 1 report reports only
- T1538 1 report reports only
- T1543 1 report reports only
- T1543.002 1 report reports only
- T1543.004 1 report reports only
- T1546 1 report reports only
- T1546.003 1 report reports only
- T1546.004 1 report reports only
- T1546.008 1 report reports only
- T1546.012 1 report reports only
- T1547 1 report reports only
- T1547.002 1 report reports only
- T1547.005 1 report reports only
- T1547.009 1 report reports only
- T1548.002 1 report in ATT&CK
- T1550 1 report reports only
- T1550.001 1 report reports only
- T1550.002 1 report reports only
- T1552 1 report reports only
- T1554 1 report reports only
- T1555 1 report reports only
- T1556 1 report reports only
- T1556.006 1 report reports only
- T1556.009 1 report reports only
- T1558.003 1 report reports only
- T1559 1 report reports only
- T1560.002 1 report reports only
- T1564.004 1 report reports only
- T1565 1 report reports only
- T1565.001 1 report reports only
- T1566.003 1 report reports only
- T1567.001 1 report reports only
- T1567.002 1 report reports only
- T1569 1 report reports only
- T1569.002 1 report reports only
- T1573 1 report reports only
- T1573.002 1 report in ATT&CK
- T1574 1 report reports only
- T1574.011 1 report reports only
- T1578 1 report reports only
- T1580 1 report reports only
- T1583.006 1 report reports only
- T1584 1 report reports only
- T1584.001 1 report reports only
- T1584.004 1 report reports only
- T1585 1 report reports only
- T1585.002 1 report reports only
- T1586.002 1 report reports only
- T1587 1 report reports only
- T1587.003 1 report reports only
- T1588 1 report reports only
- T1588.001 1 report reports only
- T1588.002 1 report in ATT&CK
- T1588.003 1 report reports only
- T1588.004 1 report reports only
- T1588.007 1 report reports only
- T1589.002 1 report reports only
- T1590.005 1 report reports only
- T1591 1 report reports only
- T1591.002 1 report reports only
- T1592 1 report reports only
- T1595.001 1 report reports only
- T1598 1 report reports only
- T1602 1 report reports only
- T1602.001 1 report reports only
- T1602.002 1 report reports only
- T1608.003 1 report reports only
- T1608.004 1 report reports only
- T1608.005 1 report reports only
- T1613 1 report reports only
- T1614 1 report reports only
- T1614.001 1 report reports only
- T1615 1 report reports only
- T1619 1 report reports only
- T1622 1 report reports only
- T1652 1 report reports only
- T1654 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2008-3431 KEV
- CVE-2012-0151 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-5469
- CVE-2012-5687
- CVE-2013-3900 KEV
- CVE-2013-5947
- CVE-2014-0160 KEV
- CVE-2014-0346
- CVE-2014-1225
- CVE-2014-1812 KEV ransomware
- CVE-2014-2962
Show all 233 CVEs Show fewer
- CVE-2014-4019
- CVE-2014-4113 KEV
- CVE-2014-4114 KEV
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-1641 KEV
- CVE-2015-1770 KEV
- CVE-2015-2051 KEV
- CVE-2015-2419 KEV
- CVE-2015-2545 KEV
- CVE-2015-7036
- CVE-2015-7248
- CVE-2015-7254
- CVE-2016-0167 KEV ransomware
- CVE-2016-0189 KEV ransomware
- CVE-2016-4117 KEV ransomware
- CVE-2016-5195 KEV
- CVE-2017-0144 KEV ransomware
- CVE-2017-0176
- CVE-2017-0199 KEV ransomware
- CVE-2017-0262 KEV
- CVE-2017-10271 KEV ransomware
- CVE-2017-1099
- CVE-2017-11292 KEV
- CVE-2017-11774 KEV
- CVE-2017-1182
- CVE-2017-11822
- CVE-2017-11882 KEV ransomware
- CVE-2017-12149 KEV ransomware
- CVE-2017-12824
- CVE-2017-15399
- CVE-2017-15944 KEV
- CVE-2017-5638 KEV ransomware
- CVE-2017-6327 KEV
- CVE-2017-6328
- CVE-2017-8291 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2017-9805 KEV
- CVE-2018-0296 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-0824 KEV
- CVE-2018-10561 KEV
- CVE-2018-1207
- CVE-2018-13379 KEV ransomware
- CVE-2018-15961 KEV
- CVE-2018-15982 KEV ransomware
- CVE-2018-4878 KEV ransomware
- CVE-2018-5407
- CVE-2018-7600 KEV ransomware
- CVE-2018-7602 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8405 KEV ransomware
- CVE-2018-8406 KEV ransomware
- CVE-2018-8581 KEV ransomware
- CVE-2018-8611 KEV
- CVE-2018-8639 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0803 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-11043 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-11580 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-1458 KEV ransomware
- CVE-2019-16098
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-16920 KEV
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-3396 KEV ransomware
- CVE-2019-3398 KEV
- CVE-2019-8394 KEV
- CVE-2019-8457
- CVE-2019-8577
- CVE-2019-8598
- CVE-2019-8600
- CVE-2019-8602
- CVE-2019-9621 KEV
- CVE-2020-0601 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0787 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-10198
- CVE-2020-1040 KEV
- CVE-2020-10826
- CVE-2020-10827
- CVE-2020-116511
- CVE-2020-11652 KEV
- CVE-2020-11899 KEV
- CVE-2020-1350 KEV
- CVE-2020-13756
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-14750 KEV
- CVE-2020-14882 KEV
- CVE-2020-1599
- CVE-2020-2021 KEV ransomware
- CVE-2020-3125
- CVE-2020-3529
- CVE-2020-5902 KEV ransomware
- CVE-2020-6789
- CVE-2020-7961 KEV
- CVE-2020-8243 KEV
- CVE-2020-8260 KEV
- CVE-2020-8515 KEV
- CVE-2021-1636
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-1844
- CVE-2021-1879 KEV
- CVE-2021-20016 KEV ransomware
- CVE-2021-21166 KEV
- CVE-2021-22894 KEV
- CVE-2021-22899 KEV
- CVE-2021-22900 KEV
- CVE-2021-22941 KEV ransomware
- CVE-2021-26084 KEV ransomware
- CVE-2021-26411 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-30116 KEV ransomware
- CVE-2021-30551 KEV
- CVE-2021-31195
- CVE-2021-31196 KEV
- CVE-2021-31206
- CVE-2021-31207 KEV ransomware
- CVE-2021-3156 KEV
- CVE-2021-33742 KEV
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-36798
- CVE-2021-36934 KEV
- CVE-2021-36942 KEV ransomware
- CVE-2021-4044
- CVE-2021-40444 KEV ransomware
- CVE-2021-40449 KEV ransomware
- CVE-2021-40539 KEV ransomware
- CVE-2021-4104
- CVE-2021-41379 KEV ransomware
- CVE-2021-43936
- CVE-2021-44077 KEV
- CVE-2021-44207 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-44515 KEV
- CVE-2021-44832
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-1096 KEV
- CVE-2022-21587 KEV ransomware
- CVE-2022-21882 KEV ransomware
- CVE-2022-22954 KEV ransomware
- CVE-2022-22957
- CVE-2022-22958
- CVE-2022-24086 KEV
- CVE-2022-24500
- CVE-2022-24521 KEV ransomware
- CVE-2022-24682 KEV ransomware
- CVE-2022-24934
- CVE-2022-26134 KEV ransomware
- CVE-2022-26809
- CVE-2022-26923 KEV
- CVE-2022-27924 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-30333 KEV ransomware
- CVE-2022-31199 KEV ransomware
- CVE-2022-37042 KEV ransomware
- CVE-2022-41080 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2023-0669 KEV ransomware
- CVE-2023-21746
- CVE-2023-23397 KEV
- CVE-2023-27350 KEV ransomware
- CVE-2023-27532 KEV ransomware
- CVE-2023-27997 KEV ransomware
- CVE-2023-28461 KEV ransomware
- CVE-2023-32315 KEV
- CVE-2023-3466
- CVE-2023-3467
- CVE-2023-3519 KEV ransomware
- CVE-2023-36033 KEV
- CVE-2023-38331
- CVE-2023-38831 KEV ransomware
- CVE-2023-45727 KEV
- CVE-2023-46805 KEV ransomware
- CVE-2023-48788 KEV ransomware
- CVE-2024-0012 KEV ransomware
- CVE-2024-21887 KEV ransomware
- CVE-2024-21893 KEV ransomware
- CVE-2024-21983
- CVE-2024-24919 KEV ransomware
- CVE-2024-27956
- CVE-2024-30051 KEV ransomware
- CVE-2024-3400 KEV ransomware
- CVE-2024-36401 KEV
- CVE-2024-42009 KEV
- CVE-2024-4577 KEV ransomware
- CVE-2024-47575 KEV
- CVE-2024-6473
- CVE-2024-9474 KEV ransomware
- CVE-2025-2783 KEV
- CVE-2025-31324 KEV ransomware
- CVE-2025-55182 KEV ransomware
- CVE-2025-68613 KEV
- CVE-2026-1731 KEV ransomware
- CVE-2026-20127 KEV
- CVE-2026-21236
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Cobalt Group Gaffe Reveals All Targets in Attack on Financial Institutions
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Cobalt Group Gaffe Reveals All Targets in Attack on Financial Institutions
-
Cobalt Group - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Cobalt Group - Threat Group Cards: A Threat Actor Encyclopedia
-
First Activities of Cobalt Group in 2018: Spear-phishing Russian Banks
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor First Activities of Cobalt Group in 2018: Spear-phishing Russian Banks
Show all 772 reports Show fewer
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor More_eggs (Malware Family)
-
Team46 and TaxOff: two sides of the same coin
The original link failed its last check. Original publisher Detailsfor Team46 and TaxOff: two sides of the same coin
-
logpoint-etpr-a-comprehensive-overview-on-stealer-malware-families.pdf
The original link failed its last check. Original publisher Detailsfor logpoint-etpr-a-comprehensive-overview-on-stealer-malware-families.pdf
-
Spam trends campaigns senior superlatives 2023
The original link failed its last check. Original publisher Detailsfor Spam trends campaigns senior superlatives 2023
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Unmasking Venom Spider
-
The original link failed its last check. Original publisher Detailsfor https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/trojanized-onenote-document-leads-to-formbook-malware/
-
Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
The original link failed its last check. Original publisher Detailsfor Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Russian Ransomware C2 Network Discovered in Censys Data
The original link failed its last check. Original publisher Detailsfor Russian Ransomware C2 Network Discovered in Censys Data
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hackers Spearphish Corporate Hiring Managers with Poisoned Resumes, Infecting Them with the More_Eggs Malware, Warns eSentire
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Legitimate Sites used as Cobalt Strike C2s against Indian Government
The original link failed its last check. Original publisher Detailsfor Legitimate Sites used as Cobalt Strike C2s against Indian Government
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor 2021trends.pdf
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
VMware Exposing Malware In Linux Based Multi Cloud Environments
The original link failed its last check. Original publisher Detailsfor VMware Exposing Malware In Linux Based Multi Cloud Environments
-
Winnti is Coming - Evolution after Prosecution@HITCON2021
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Winnti is Coming - Evolution after Prosecution@HITCON2021
-
sneak-peek-ch1-2-finding-beacons-in-the-dark.pdf
The original link failed its last check. Original publisher Detailsfor sneak-peek-ch1-2-finding-beacons-in-the-dark.pdf
-
Masters of Mimicry: new APT group ChamelGang and its arsenal
The original link failed its last check. Original publisher Detailsfor Masters of Mimicry: new APT group ChamelGang and its arsenal
-
Masters of Mimicry: new APT group ChamelGang and its arsenal
The original link failed its last check. Original publisher Detailsfor Masters of Mimicry: new APT group ChamelGang and its arsenal
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
APT Cobalt Strike Campaign targeting Slovakia (DEF CON talk)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Cobalt Strike Campaign targeting Slovakia (DEF CON talk)
-
report-old-dogs-new-tricks.pdf
The original link failed its last check. Original publisher Detailsfor report-old-dogs-new-tricks.pdf
-
Ryuk Ransomware Now Targeting Webservers
The original link failed its last check. Original publisher Detailsfor Ryuk Ransomware Now Targeting Webservers
-
Looks like the page you're looking for doesn't exist or has moved.
The original link failed its last check. Original publisher Detailsfor Looks like the page you're looking for doesn't exist or has moved.
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CTIR_casestudy_2.pdf
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CTIR_casestudy_1.pdf
-
the-operations-of-winnti-group.pdf
The original link failed its last check. Original publisher Detailsfor the-operations-of-winnti-group.pdf
-
PaaS, or how hackers evade antivirus software
The original link failed its last check. Original publisher Detailsfor PaaS, or how hackers evade antivirus software
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hackers Spearphish Professionals on LinkedIn with Fake Job Offers, Infecting them with Malware, Warns eSentire
-
report-bb-2021-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor report-bb-2021-threat-report.pdf
-
Technical Analysis of Operation Diànxùn
The original link failed its last check. Original publisher Detailsfor Technical Analysis of Operation Diànxùn
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
2020-q2-spamhaus-botnet-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor 2020-q2-spamhaus-botnet-threat-report.pdf
-
In-Memory shellcode decoding to evade AVs/EDRs
The original link failed its last check. Original publisher Detailsfor In-Memory shellcode decoding to evade AVs/EDRs
-
More evil- A deep look at Evilnum and its toolset
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor More evil- A deep look at Evilnum and its toolset
-
More evil_ A deep look at Evilnum and its toolset _ WeLiveSecurity
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor More evil_ A deep look at Evilnum and its toolset _ WeLiveSecurity
-
Cobalt: tactics and tools update
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cobalt: tactics and tools update
-
Cobalt- tactics and tools update
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cobalt- tactics and tools update
-
Cobalt: tactics and tools update
The original link failed its last check. Original publisher Detailsfor Cobalt: tactics and tools update
-
CTNT_Q1_2020_COVID-Report_Final.pdf
The original link failed its last check. Original publisher Detailsfor CTNT_Q1_2020_COVID-Report_Final.pdf
-
Catching APT41 exploiting a zero-day vulnerability
The original link failed its last check. Detailsfor Catching APT41 exploiting a zero-day vulnerability
-
cybersecurity-threatscape-2019-q4-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor cybersecurity-threatscape-2019-q4-eng
-
Report2020CrowdStrikeGlobalThreatReport
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2020CrowdStrikeGlobalThreatReport
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor [CB19] Cyber Threat Landscape in Japan – Revealing Threat in the Shadow by Chi En Shen (Ashley) Oleg Bondarenko
-
The original link failed its last check. Original publisher Detailsfor Aarhus_miniseminar_291118.pdf
-
TA2101 plays government imposter to distribute malware to German, Italian, and US organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA2101 plays government imposter to distribute malware to German, Italian, and US organizations
-
PureLocker- New Ransomware-as-a-Service Being Used in Targeted Attacks Against Servers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor PureLocker- New Ransomware-as-a-Service Being Used in Targeted Attacks Against Servers
-
The original link failed its last check. Original publisher Detailsfor Analytics
-
Operation-Taskmasters-2019-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation-Taskmasters-2019-eng
-
2019 Cyber Threatscape Report I Accenture
The original link failed its last check. Original publisher Detailsfor 2019 Cyber Threatscape Report I Accenture
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Talos Blog __ Cisco Talos Intelligence Group - Comprehensive Threat Intelligence_ 10 years of virtual dynamite_ A high-level retrospective of ATM malware
-
10 years of virtual dynamite- A high-level retrospective of ATM malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 10 years of virtual dynamite- A high-level retrospective of ATM malware
-
mpressioncss_ta_report_2019.pdf
The original link failed its last check. Original publisher Detailsfor mpressioncss_ta_report_2019.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2019GlobalThreatReport
-
The original link failed its last check. Original publisher Detailsfor CrowdStrike_GTR_2019.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Golden Chickens- Uncovering A Malware-as-a-Service (MaaS) Provider and Two New Threat Actors Using It
-
New Techniques to Uncover and Attribute Cobalt Gang Commodity Builders and Infrastructure Revealed
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Techniques to Uncover and Attribute Cobalt Gang Commodity Builders and Infrastructure Revealed
-
Software Description- More_eggs
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Software Description- More_eggs
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cobalt Group 2.0
-
Meet CrowdStrike’s Adversary of the Month for September- COBALT SPIDER
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Meet CrowdStrike’s Adversary of the Month for September- COBALT SPIDER
-
Cybercriminals Increasingly Trying to Ensnare the Big Financial Fish
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cybercriminals Increasingly Trying to Ensnare the Big Financial Fish
-
New modular downloaders fingerprint systems - Part 3- CobInt
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New modular downloaders fingerprint systems - Part 3- CobInt
-
Double the Infection, Double the Fun
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Double the Infection, Double the Fun
-
Cobalt Hacking Group Tests Banks In Russia and Romania
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cobalt Hacking Group Tests Banks In Russia and Romania
-
Double the Infection, Double the Fun | NETSCOUT
The original link failed its last check. Original publisher Detailsfor Double the Infection, Double the Fun | NETSCOUT
-
Double the Infection, Double the Fun
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Double the Infection, Double the Fun
-
Accenture-Cyber-Threatscape-Report-2018.pdf
The original link failed its last check. Original publisher Detailsfor Accenture-Cyber-Threatscape-Report-2018.pdf
-
Arrests Put New Focus on CARBON SPIDER Adversary Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Arrests Put New Focus on CARBON SPIDER Adversary Group
-
Multiple Cobalt Personality Disorder
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Multiple Cobalt Personality Disorder
-
Cobalt Renaissance- new attacks and joint operations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cobalt Renaissance- new attacks and joint operations
-
Spear-phishing campaign leveraging on MSXSL
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Spear-phishing campaign leveraging on MSXSL
-
First Activities of Cobalt Group in 2018- Spear Phishing Russian Banks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor First Activities of Cobalt Group in 2018- Spear Phishing Russian Banks
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Gaffe Reveals Full List of Targets in Spear Phishing Attack Using Cobalt Strike Against Financial Institutions
-
Cobalt Strikes Again, Spam Runs Target Russian Banks
The original link failed its last check. Original publisher Detailsfor Cobalt Strikes Again, Spam Runs Target Russian Banks
-
Cobalt Strikes Again- Spam Runs Use Macros and CVE-2017-8759 Exploit Against Russian Banks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cobalt Strikes Again- Spam Runs Use Macros and CVE-2017-8759 Exploit Against Russian Banks
-
The Formidable FormBook Form Grabber | NETSCOUT
The original link failed its last check. Original publisher Detailsfor The Formidable FormBook Form Grabber | NETSCOUT
-
The original link failed its last check. Original publisher Detailsfor Cobalt-2017-eng.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Secrets of Cobalt
-
Emails with Backdoor Targets Russian Businesses
The original link failed its last check. Original publisher Detailsfor Emails with Backdoor Targets Russian Businesses
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Positive Technologies - learn and secure : Cobalt strikes back: an evolving multinational threat to finance
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Word Intruder Integrates CVE-2017-0199, Utilized by Cobalt Group to Target Financial Institutions
-
McAfee Labs Quarterly Threat Report June 2017
The original link failed its last check. Original publisher Detailsfor McAfee Labs Quarterly Threat Report June 2017
-
The original link failed its last check. Original publisher Detailsfor GitHub - R3MRUM/loki-parse: A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security researchers who want to know what data is being exfiltrated to the C2, bot tracking, etc...
-
Taiwan ATM heist linked to European hacking spree- security firm
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Taiwan ATM heist linked to European hacking spree- security firm
-
The original link failed its last check. Original publisher Detailsfor Cobalt-Snatch-eng.pdf
Newest first. Details opens the report in Explore.