Threat actor · all actors
Cobalt GroupG0080 unknown
aka Cobalt Group, GOLD KINGSWOOD, Cobalt Gang, Cobalt Spider, Cobalt, G0080, Mule Libra
Last updated: 2026-08-20
About this actor
[Cobalt Group](https://attack.mitre.org/groups/G0080) is a financially motivated threat group that has primarily targeted financial institutions since at least 2016. The group has conducted intrusions to steal money via targeting ATM systems, card processing, payment systems and SWIFT systems. [Cobalt Group](https://attack.mitre.org/groups/G0080) has mainly targeted banks in Eastern Europe, Central Asia, and Southeast Asia. One of the alleged leaders was arrested in Spain in early 2018, but the group still appears to be active. The group has been known to target organizations in order to use their access to then compromise additional victims.(Citation: Talos Cobalt Group July 2018)(Citation: PTSecurity Cobalt Group Aug 2017)(Citation: PTSecurity Cobalt Dec 2016)(Citation: Group IB Cobalt Aug 2017)(Citation: Proofpoint Cobalt June 2017)(Citation: RiskIQ Cobalt Nov 2017)(Citation: RiskIQ Cobalt Jan 2018) Reporting indicates there may be links between [Cobalt Group](https://attack.mitre.org/groups/G0080) and both the malware [Carbanak](https://attack.mitre.org/software/S0030) and the group [Carbanak](https://attack.mitre.org/groups/G0008).(Citation: Europol Cobalt Mar 2018)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
CrowdStrikenation-animal names
Secureworkscolour-metal names
Palo Alto Unit 42constellation names
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 52 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1021Remote Services ↗T1021.001Remote Desktop Protocol ↗T1027Obfuscated Files or Information ↗T1027.010Command Obfuscation ↗T1037Boot or Logon Initialization Scripts ↗T1037.001Logon Script (Windows) ↗T1046Network Service Discovery ↗T1053Scheduled Task/Job ↗T1053.005Scheduled Task ↗T1055Process Injection ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.003Windows Command Shell ↗T1059.005Visual Basic ↗T1059.007JavaScript ↗T1068Exploitation for Privilege Escalation ↗T1070Indicator Removal ↗T1070.004File Deletion ↗T1071Application Layer Protocol ↗T1071.001Web Protocols ↗T1071.004DNS ↗T1105Ingress Tool Transfer ↗T1195Supply Chain Compromise ↗T1195.002Compromise Software Supply Chain ↗T1203Exploitation for Client Execution ↗T1204User Execution ↗T1204.001Malicious Link ↗T1204.002Malicious File ↗T1218System Binary Proxy Execution ↗T1218.003CMSTP ↗T1218.008Odbcconf ↗T1218.010Regsvr32 ↗T1219Remote Access Tools ↗T1220XSL Script Processing ↗T1518Software Discovery ↗T1518.001Security Software Discovery ↗T1543Create or Modify System Process ↗T1543.003Windows Service ↗T1547Boot or Logon Autostart Execution ↗T1547.001Registry Run Keys / Startup Folder ↗T1548Abuse Elevation Control Mechanism ↗T1548.002Bypass User Account Control ↗T1559Inter-Process Communication ↗T1559.002Dynamic Data Exchange ↗T1566Phishing ↗T1566.001Spearphishing Attachment ↗T1566.002Spearphishing Link ↗T1572Protocol Tunneling ↗T1573Encrypted Channel ↗T1573.002Asymmetric Cryptography ↗T1588Obtain Capabilities ↗T1588.002Tool ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 42 / 52 | 81% |
CM-6 | 40 / 52 | 77% |
CM-2 | 39 / 52 | 75% |
SI-3 | 35 / 52 | 67% |
CM-7 | 33 / 52 | 63% |
CA-7 | 28 / 52 | 54% |
AC-3 | 23 / 52 | 44% |
SC-7 | 22 / 52 | 42% |
AC-4 | 21 / 52 | 40% |
AC-6 | 21 / 52 | 40% |
SI-7 | 21 / 52 | 40% |
RA-5 | 20 / 52 | 38% |
AC-2 | 19 / 52 | 37% |
CM-8 | 17 / 52 | 33% |
SI-2 | 17 / 52 | 33% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- Patchwork 0.37
- FIN8 0.35
- Silence 0.34
- Sidewinder 0.32
- TA2541 0.32