🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
COBALT GROUP

/actor/cobalt-group/  ·  0 intel reports

Year Established
2016
Attribution
Russia/Eastern Europe
Motivation
Financial
Modus Operandi (MO)
ATM jackpotting, SWIFT banking attacks, spear-phishing financial institutions, Cobalt Strike abuse
Primary Aliases
GOLD KINGSWOOD, Cobalt Gang

Cobalt Group (not to be confused with the legitimate security tool Cobalt Strike, though the group heavily abused it) is a financially motivated cybercriminal organisation that conducted some of the most technically sophisticated attacks ever recorded against the global banking and financial services sector. Active from approximately 2016, the group is assessed to have stolen over $1 billion USD from over 100 financial institutions across 40+ countries through ATM jackpotting attacks, SWIFT banking system fraud, and card processing system compromise.

The group's ATM jackpotting operations were particularly innovative: by gaining access to bank internal networks through spear-phishing campaigns targeting bank employees, Cobalt Group could send commands to ATM machines instructing them to dispense cash to waiting money mules at pre-arranged times , enabling near-simultaneous cash extraction from hundreds of ATMs across entire countries in coordinated "jackpotting" operations that generated millions of dollars in minutes.

Cobalt Group was a heavy user of the legitimate penetration testing tool Cobalt Strike for post-exploitation activities , a practice so prevalent that it contributed to the tool becoming synonymous with malicious use and prompted the security community to develop detection signatures specifically for Cobalt Strike's malleable C2 profiles. The group's abuse of legitimate red team tooling to blend with authorised security testing activity represented an early example of a technique now widespread across the threat landscape.

The alleged leader of Cobalt Group, Denis Malnev (also known as "Cobalt"), was arrested in Alicante, Spain in March 2018 in a joint operation by Europol, the Spanish National Police, and FBI. Despite this arrest, Cobalt Group operations continued, demonstrating the resilience of criminal organisations to leadership disruption and suggesting the group had distributed leadership or quickly promoted existing senior members to replace arrested personnel.

Threat Mitigation and Strategic Hardening: Network defense against campaigns linked to Cobalt Group requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our Cyber Risk Checker and report critical indicators via Secure Drop.

STATUS: ACTIVE CLASSIFICATION: CYBERCRIME SYNDICATE LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles