[ << ALL_FEED ]

In early 2024, our team identified the use of Cobint malware in customer infrastructures

More in Threat actors

In early 2024, our team identified the use of the Cobint malware in customers’ infrastructures 🥷

This malware is actively used by the (Ex)Cobalt group in attacks on Russian companies (read more about Cobint in our blog: here and here).

The attacks used a specific PowerShell loader that unpacked and executed the payload in memory, and also downloaded the next stage from a C2 server.

An interesting feature of the loader — the use of the Windows API function InternetReadFile to download the stage from the C2 server, as a result of which the encrypted stage may remain in the Internet Explorer cache, which is located at:

\%User%\AppData\Local\Microsoft\Windows\InetCache\IE\

Often the malware is launched under the System or NetworkService credentials; in this case, an indicator may be the appearance in the cache of the corresponding users of files with long random names, for example:
\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\INetCache\IE\adubiyzhofbsewzzvbyesa[1]
\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\kmduvjhwxevabeyuzafwe[1]

Analysis of the Cobint malware, useful tricks, as well as ways to automate payload decryption — see the article on “xakep.ru”.

#detect #malware #dfir #cobint #excobalt
@ptescalator

More from oUth0R

More from oUth0R

More in Threat actors