A Shortcut to Compromise: Cobalt Gang phishing campaign
ID: da79d9e7-3565-579c-8ea4-55d979f04bb0
STIX ID: report--da79d9e7-3565-579c-8ea4-55d979f04bb0
Feed Name: Group-IB Blog
**Executive summary:** In August 2019 the Cobalt Gang targeted financial institutions with spearphishing emails containing an IMG with a weaponized LNK that launched an obfuscated PowerShell (1.ps1); the script decoded and wrote a CobInt stager, used UAC bypass techniques (eventvwr.exe or fodhelper.exe) to execute it, and ultimately delivered Cobalt Strike beacons. The report includes hashes, delivery URLs (e.g. swift-customer.com, valorleads.com, safestaticfirefox.com), a victim SID, and a function-level analysis mapping the activity to MITRE ATT&CK.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
