🌐Cobalt Group
🌐 Cobalt Group is a tracked threat actor in the Clankerusecase corpus. Attributed to ??. Primary motivation: Criminal. We map 26 detection use cases to this actor across 52 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-07-24 to 2026-07-24.
crit 1
26Use cases
1Articles
52Techniques
10IOCs
Known aliases
Cobalt GroupCobalt GangCobalt SpiderGOLD KINGSWOOD
Top techniques
All other tracked techniques
T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1021.002 · SMB/Windows Admin SharesT1027.010 · Command ObfuscationT1037.001 · Logon Script (Windows)T1046 · Network Service DiscoveryT1053.005 · Scheduled TaskT1055 · Process InjectionT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1059.007 · JavaScriptT1068 · Exploitation for Privilege EscalationT1070.004 · File DeletionT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.004 · DNST1098.001 · Additional Cloud CredentialsT1102 · Web ServiceT1105 · Ingress Tool TransferT1176 · Software ExtensionsT1185 · Browser Session HijackingT1195.002 · Compromise Software Supply ChainT1203 · Exploitation for Client ExecutionT1204.001 · Malicious LinkT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1218 · System Binary Proxy ExecutionT1218.003 · CMSTPT1218.008 · OdbcconfT1218.010 · Regsvr32T1219 · Remote Access ToolsT1220 · XSL Script ProcessingT1486 · Data Encrypted for ImpactT1518.001 · Security Software DiscoveryT1528 · Steal Application Access TokenT1539 · Steal Web Session CookieT1543.003 · Windows ServiceT1547.001 · Registry Run Keys / Startup FolderT1548.002 · Bypass User Account ControlT1555.003 · Credentials from Web BrowsersT1559.002 · Dynamic Data ExchangeT1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1569.002 · Service ExecutionT1572 · Protocol TunnelingT1573.002 · Asymmetric CryptographyT1588.002 · Tool
Detection use cases (26)
Cobalt Group (GOLD KINGSWOOD) Equation Editor exploit chain — EQNEDT32.EXE spawning script hosts Cobalt Group CobInt stager — signed-binary proxy fetching remote scriptlet (regsvr32/odbcconf/msxsl → public egress) TAG-195 ClickFix OCX payload executed via regsvr32 (TinyEgg install) TAG-195 Golden Chickens C2 beacon to known staging/C2 infrastructure ChromEggscalator: Chromium launched with --remote-debugging-port for cookie/credential theft Beaconing — periodic outbound to small set of destinations Network connections to article IPs / domains Suspicious browser extension installation Infostealer — non-browser process accessing browser cookie/login DBs Phishing-link click correlated to endpoint execution Email attachment opened from external sender Office app spawning script/LOLBin child process OAuth consent / suspicious app grant Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process AI/LLM Framework Web Service Spawns Shell or Network Tool (Agent-Framework Unauthenticated RCE) Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Developer package install spawning script-host with non-registry C2 within 5 minutes Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transitionThreat-intel articles (1)
Tracked indicators
Domains (6)
ahdaratlegalservices.com aurekh.com paysolutions.ink screenly.cam thessa.trackgrid.net xtrafftrck.netIP addresses (4)
108.61.209.100 65.20.102.161 65.20.105.177 70.34.205.43