COBALT GYPSY

Threat Actor updated 7 months ago (2024-05-05T01:17:34.945Z)
Download STIX
Preview STIX
Cobalt Gypsy, also known as APT34, Helix Kitten, Hazel Sandstorm, and OilRig, is an Iranian advanced persistent threat operation that has been active since at least 2014. This threat actor has a history of targeting sectors such as telecommunications, government, defense, oil, and financial services primarily in the Middle East. The group's modus operandi typically involves spear-phishing lures leading to the deployment of various backdoors, with its activities bearing similarities to those of other groups like COBALT TRINITY (also known as Elfin and APT33). On October 2, 2023, Cobalt Gypsy's cyberespionage capabilities were significantly bolstered with the introduction of the novel Menorah malware. This new tool was deployed in a spear-phishing campaign, which notably included a Saudi Arabia-based organization among its targets. The Menorah malware represents a significant addition to the group's arsenal, enhancing their ability to conduct sophisticated cyberespionage operations. The cybersecurity industry should remain vigilant in monitoring the activities of Cobalt Gypsy and similar threat actors. The introduction of the Menorah malware demonstrates the group's ongoing commitment to developing new tools and tactics for conducting espionage. It also underscores the need for organizations, particularly those in the targeted sectors and regions, to maintain robust cybersecurity defenses and awareness of potential threats.
Description last updated: 2024-05-05T00:27:04.886Z
What's your take? (Question 1 of 1)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
OilRig is a possible alias for COBALT GYPSY. OilRig, also known as APT34, Earth Simnavaz, Evasive Serpens, and other names, is a well-known threat actor in the cybersecurity industry. This group has been particularly active in targeting entities in the Middle East, including critical infrastructure and telecommunications organizations. One of
2
APT34 is a possible alias for COBALT GYPSY. APT34, a threat actor suspected to be linked to Iran, has been operational since at least 2014 and is involved in long-term cyber espionage operations largely focused on reconnaissance efforts. The group targets a variety of sectors including financial, government, energy, chemical, and telecommunic
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the COBALT GYPSY Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more