logo

A Shortcut to Compromise: Cobalt Gang phishing campaign

ID: da79d9e7-3565-579c-8ea4-55d979f04bb0

STIX ID: report--da79d9e7-3565-579c-8ea4-55d979f04bb0

Feed Name: Group-IB Blog

Threat Score
78/100

Date Published: 2019-12-20

Date Updated: 2026-04-27

...
...

**Executive summary:** In August 2019 the Cobalt Gang targeted financial institutions with spearphishing emails containing an IMG with a weaponized LNK that launched an obfuscated PowerShell (1.ps1); the script decoded and wrote a CobInt stager, used UAC bypass techniques (eventvwr.exe or fodhelper.exe) to execute it, and ultimately delivered Cobalt Strike beacons. The report includes hashes, delivery URLs (e.g. swift-customer.com, valorleads.com, safestaticfirefox.com), a victim SID, and a function-level analysis mapping the activity to MITRE ATT&CK.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.