PULSE NAME
Cobalt Strikes Again: Spam Runs Use Macros and CVE-2017-8759 Exploit Against Russian Banks
WHITE cottie2 2017-11-25 Modified: 2017-11-25
0
IOCs
LOW VOLUME
From Trend Micro Blog: The waves of backdoor-laden spam emails we observed during June and July that targeted Russian-speaking businesses were part of bigger campaigns. The culprit appears to be the Cobalt hacking group, based on the techniques used. In their recent campaigns, Cobalt used two different infection chains, with social engineering hooks that were designed to invoke a sense of urgency in its recipients—the bank’s employees. Cobalt was named after Cobalt Strike, a multifunctional penetration testing tool similar to Metasploit.
Indicators of Compromise (0)
All
No indicators.