Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0080
MITRE ATT&CK Group

Cobalt Group (G0080)

GOLD KINGSWOODCobalt GangCobalt Spider
ShareXLinkedInRedditHN

[Cobalt Group](https://attack.mitre.org/groups/G0080) is a financially motivated threat group that has primarily targeted financial institutions since at least 2016. The group has conducted intrusions to steal money via targeting ATM systems, card processing, payment systems and SWIFT systems. [Cobalt Group](https://attack.mitre.org/groups/G0080) has mainly targeted banks in Eastern Europe, Central Asia, and Southeast Asia. One of the alleged leaders was arrested in Spain in early 2018, but the group still appears to be active. The group has been known to target organizations in order to use their access to then compromise additional victims.(Citation: Talos Cobalt Group July 2018)(Citation: PTSecurity Cobalt Group Aug 2017)(Citation: PTSecurity Cobalt Dec 2016)(Citation: Group IB Cobalt Aug 2017)(Citation: Proofpoint Cobalt June 2017)(Citation: RiskIQ Cobalt Nov 2017)(Citation: RiskIQ Cobalt Jan 2018) Reporting indicates there may be links between [Cobalt Group](https://attack.mitre.org/groups/G0080) and both the malware [Carbanak](https://attack.mitre.org/software/S0030) and the group [Carbanak](https://attack.mitre.org/groups/G0008).(Citation: Europol Cobalt Mar 2018)

▪Techniques used (34)

T1566.001Spearphishing AttachmentT1105Ingress Tool TransferT1027.010Command ObfuscationT1053.005Scheduled TaskT1218.008OdbcconfT1195.002Compromise Software Supply ChainT1518.001Security Software DiscoveryT1559.002Dynamic Data ExchangeT1204.002Malicious FileT1068Exploitation for Privilege EscalationT1218.003CMSTPT1218.010Regsvr32T1055Process InjectionT1059.001PowerShellT1588.002ToolT1021.001Remote Desktop ProtocolT1059.005Visual BasicT1203Exploitation for Client ExecutionT1070.004File DeletionT1548.002Bypass User Account ControlT1220XSL Script ProcessingT1071.004DNST1059.007JavaScriptT1566.002Spearphishing LinkT1204.001Malicious LinkT1059.003Windows Command ShellT1071.001Web ProtocolsT1547.001Registry Run Keys / Startup FolderT1572Protocol TunnelingT1573.002Asymmetric CryptographyT1543.003Windows ServiceT1219Remote Access ToolsT1046Network Service DiscoveryT1037.001Logon Script (Windows)

▪Software used (6)

S0002MimikatztoolS0284More_eggsmalwareS0646SpicyOmelettemalwareS0195SDeletetoolS0154Cobalt StrikemalwareS0029PsExectool
G0080on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.