In early 2024, our team identified the use of Cobint malware in customer infrastructures

More in Threat actors
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- We will croc you
We will croc you 👻 PhantomCore continues to actively exploit misconfigurations in 1C to attack Russian…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- ⚡Fake news — THAT'S ALL
⚡Fake news — B U L L S H I T PT ESC specialists discovered an…
In early 2024, our team identified the use of the Cobint malware in customers’ infrastructures 🥷
This malware is actively used by the (Ex)Cobalt group in attacks on Russian companies (read more about Cobint in our blog: here and here).
The attacks used a specific PowerShell loader that unpacked and executed the payload in memory, and also downloaded the next stage from a C2 server.
An interesting feature of the loader — the use of the Windows API function InternetReadFile to download the stage from the C2 server, as a result of which the encrypted stage may remain in the Internet Explorer cache, which is located at:
\%User%\AppData\Local\Microsoft\Windows\InetCache\IE\
Often the malware is launched under the System or NetworkService credentials; in this case, an indicator may be the appearance in the cache of the corresponding users of files with long random names, for example:
\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\INetCache\IE\adubiyzhofbsewzzvbyesa[1]
\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\kmduvjhwxevabeyuzafwe[1]
Analysis of the Cobint malware, useful tricks, as well as ways to automate payload decryption — see the article on “xakep.ru”.


#detect #malware #dfir #cobint #excobalt
@ptescalator
More in Threat actors
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- We will croc you
We will croc you 👻 PhantomCore continues to actively exploit misconfigurations in 1C to attack Russian…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- ⚡Fake news — THAT'S ALL
⚡Fake news — B U L L S H I T PT ESC specialists discovered an…






