PULSE NAME
Cobalt Group Gaffe Reveals All Targets in Attack on Financial Institutions
WHITE AlienVault 2017-11-29 Modified: 2017-11-29
3
IOCs
LOW VOLUME
In a recent spear-phishing campaign, the Cobalt Hacking Group used a remote code execution vulnerability in Microsoft Office software to connect to its command and control server via Cobalt Strike. However, they gave up much more information than they intended. On Tuesday, November 21, a massive spear-phishing campaign began targeting individual employees at various financial institutions, mostly in Russia and Turkey. Purporting to provide info on changes to ‘SWIFT’ terms, the email contained a single attachment with no text in the body.
Indicators of Compromise (3)
All FileHash-MD5 CVE
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 d46df9eacfe7ff75e098942e541d0f18 2017-11-29
FileHash-MD5 f360d41a0b42b129f7f0c29f98381416 2017-11-29
CVE CVE-2017-11882 2017-11-29