← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Cobalt Group Gaffe Reveals All Targets in Attack on Financial Institutions
In a recent spear-phishing campaign, the Cobalt Hacking Group used a remote code execution vulnerability in Microsoft Office software to connect to its command and control server via Cobalt Strike. However, they gave up much more information than they intended.
On Tuesday, November 21, a massive spear-phishing campaign began targeting individual employees at various financial institutions, mostly in Russia and Turkey. Purporting to provide info on changes to ‘SWIFT’ terms, the email contained a single attachment with no text in the body.
Indicators of Compromise (3)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | d46df9eacfe7ff75e098942e541d0f18 | — | 2017-11-29 | |
| FileHash-MD5 | f360d41a0b42b129f7f0c29f98381416 | — | 2017-11-29 | |
| CVE | CVE-2017-11882 | — | 2017-11-29 |
References (1)