not MITRE’s ATT&CK Group
Cobalt Group
How MITRE ATT&CK characterizes this group1: Cobalt Group is a financially motivated threat group that has primarily targeted financial institutions since at least 2016. The group has conducted intrusions to steal money via targeting ATM systems, card processing, payment systems and SWIFT systems. Cobalt Group has mainly targeted banks in Eastern Europe, Central Asia, and Southeast Asia. One of the alleged leaders was arrested in Spain in early 2018, but the group still appears to be active. The…
Origin / sponsor: not established from a curated public advisory — see Coverage & confidence. Not asserted here.
Read as a financially-motivated operator.
A crimeware classification means the objective is money — access brokering, theft, fraud, or commodity malware. Volume and opportunism over stealth; the path tends to monetize fast. All tradecraft below is sourced to MITRE ATT&CK.
Known for
— signature moves, each sourced to ATT&CKTradecraft heatmap
— ATT&CK techniques mapped onto the five attacker-outcome narrativesEach row is a documented technique (MITRE ATT&CK). Each column is one of the five attacker-outcome narratives a defender funds against. A filled cell means this technique’s own ATT&CK tactic defensibly advances that outcome. The mapping of technique→outcome is our editorial alignment over ATT&CK's tactic data, not a separately-sourced MITRE edge. A filled cell means one of the technique's own ATT&CK tactics defensibly advances that outcome; enabler tactics (C2, Defense Evasion, Discovery) heat no column.
Reach: this actor’s cited techniques light columns 1·2·3 — furthest is 3 · Lateral reach. (furthest-position idiom, reused from the landing map).
Arsenal
— named tools & malware ATT&CK attributes to this groupCampaign highlights
— attributed operations in the ATT&CK recordNo attributed campaigns — coverage gap
Latest activity
— with explicit confidence, and what we cannot yet claimsnapshot
The most recent cited activity in this card is the ATT&CK record itself. We do not paste a “last seen this week” line we cannot source. Recency from secondary reporting appears here only when attached to a named advisory.