Excobalt

Threat Actor updated 25 days ago (2024-08-14T09:47:19.881Z)
Download STIX
Preview STIX
ExCobalt, a cybercrime group, has been identified as a significant threat actor targeting multiple sectors within Russian organizations. This group is known for its malicious activities, which involve executing actions with harmful intent. The cybersecurity industry has monitored ExCobalt's activities closely due to the group's increasingly sophisticated methods of hacking and cyberespionage. They have demonstrated an aptitude for adopting more productive techniques, including expanded functionality for collecting victim data and increasing secrecy both inside the infected system and in communications with C2 servers. The group continues to demonstrate high levels of activity and determination in their attacks on Russian companies. ExCobalt is continually adding new tools to its arsenal and improving its techniques, indicating a high level of sophistication and adaptability. Their relentless pursuit of evolving methodologies and technologies underscores their commitment to their malicious objectives, making them a formidable threat to cybersecurity. In their recent attacks, ExCobalt utilized the Spark RAT (Remote Access Trojan) to execute commands, forming part of a multi-tool attack chain. This included the use of various tools such as Mimikatz, ProcDump, SMBExec, Metasploit, and rsocx. Each of these tools plays a unique role in the attack chain, from capturing credentials and dumping process memory to exploiting vulnerabilities and providing remote control capabilities. These aggressive tactics underline the serious threat that ExCobalt poses to targeted organizations and the broader cybersecurity landscape.
Description last updated: 2024-08-14T08:52:34.354Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Excobalt Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
Securityaffairs
a month ago
SECURITY AFFAIRS MALWARE NEWSLETTER – ROUND 6
Securityaffairs
a month ago
security-affairs-malware-newsletter-round-5
Securityaffairs
2 months ago
Security Affairs Malware Newsletter - Round 3
Securityaffairs
2 months ago
Security Affairs Malware Newsletter - Round 3
Securityaffairs
2 months ago
Security Affairs Malware Newsletter - Round 2
Securityaffairs
2 months ago
Security Affairs Malware Newsletter - Round 1
Securityaffairs
2 months ago
Security Affairs newsletter Round 478 by Pierluigi Paganini – INTERNATIONAL EDITION
Securityaffairs
2 months ago
ExCobalt Cybercrime group targets Russian organizations in multiple sectors