← Back to all threat actors

Cobalt Group

Also known as GOLD KINGSWOOD, Cobalt Gang, Cobalt Spider
Tracked as G0080

Cobalt Group is a financially motivated threat group that has primarily targeted financial institutions since at least 2016. The group has conducted intrusions to steal money via targeting ATM systems, card processing, payment systems and SWIFT systems. Cobalt Group has mainly targeted banks in Eastern Europe, Central Asia, and Southeast Asia. One of the alleged leaders was arrested in Spain in early 2018, but the group still appears to be active. The group has been known to target organizations in order to use their access to then compromise additional victims. Reporting indicates there may be links between Cobalt Group and both the malware Carbanak and the group Carbanak.

How we source and review actor profiles
Motivation
cybercrime
Sectors
financial-services
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityAlias: GOLD KINGSWOOD

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Cobalt Gang

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Cobalt Spider

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G0080

Reviewed identity mapping approved on this date.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

Cobalt GroupCanonical Name
Cobalt GangAlias
Cobalt SpiderAlias
GOLD KINGSWOODAlias
G0080Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...