Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Attacks on contracting banks: Cobalt's new approach

by The Gurus
August 2, 2017
in Editor's News
Share on FacebookShare on Twitter

Phishing emails are still useful when it comes to penetrating a bank’s information infrastructure. Intruders used to fake a sender address, but now they have a new game plan: they attack suppliers and partners and use hacked accounts of real employees to continue an attack against financial organizations. Moreover, intruders send malware files under the guise of bank notifications and attack both personal and work emails of bank employees.
 
This was revealed in Positive Technologies’ new report of Cobalt’s activities, a cybercriminal group. The criminal collective become known in 2016 after attacking a number of banks in CIS and Eastern Europe. Cobalt attacks began with targeted phishing emails to bank employees. When a worker opens a malware attachment, his or her computer gets infected, and then the attack is spread inside the bank’s network through to ATM control systems, which in turn allows a large amount of money to be stolen.
 
The group’s activity was exposed in 2016 following an investigation, in which Positive Technologies took part. Upon the investigation, Russian FinCERT began to notify financial companies. However, it hasn’t stopped the criminals: they’ve launched more sophisticated attacks in response. Here are some specific Cobalt activities revealed by Positive Technologies experts in 2017:
 

  • Fake domains. When most of the phishing emails from fake addresses were blocked by spam filters, the attackers began to use fake domains similar in spelling to addresses of bonafide organizations. Today, due to the joint efforts of Positive Technologies specialists and industry regulators, all phishing domains detected in the .ru zone, and most domains in other regions, are removed from delegation.
  • Attacks via contractors. In 2017, Cobalt began to attack various companies that work with banks and send phishing emails from their infrastructures by using accounts and email addresses of their employees. This approach guarantees that the receiver will trust the sender’s message. The success of such an attack also relies on the subject of the email: In early 2017, 60 percent of emails from Cobalt contained terms of collaboration between banks and contractors.
  • Expanding attack geography. In 2017, the list of Cobalt’s targets in CIS, Eastern Europe, and Southeastern Asia was supplemented with companies in Western Europe and North and South America: 75 percent of companies being financial organizations, and the rest were governmental organizations, telecoms, services and entertainment companies, etc. It is believed that they are an intermediate step in the attack path.
  • Emails from information security regulators’ addresses. Such emails were sent from fake domains, in particular from VISA and Mastercard payment systems, FinCERT (the Russian Central Bank’s service), and National Bank of Kazakhstan.
  • Emails to personal addresses of employees (not only corporate addresses). It is planned that emails are delivered in recipients’ working hours. The idea is that, when checking their personal email, the user will likely infect the office computer.
  • Using the latest version of Microsoft Word Intruder 8 to create documents that exploit CVE-2017-0199. Cobalt was among the first to gain access to the limited version of the MWI exploit builder, which suggests that there is a connection between the attackers and the developer of this exploit builder.

 
The authors of the study note that it is not currently possible to estimate the actual losses of companies from Cobalt activities in 2017. However, based on the scale of the group’s activities around the world, serious consequences for financial organizations in the near future can not be ruled out.
 
“In addition to banks that became traditional targets for the Cobalt group, the number of attacked companies now include other financial organizations: insurance and investment funds, brokers,” says Leigh-Anne Galloway, Cyber Security Resilliance Lead at Positive Technologies. “In 2017, Cobalt started to actively attack contractors in order to use them as a stepping stone to reach their actual target – banks. For example, one known successful attack on a bank was preceded by hacking a CIT company. To carlify, the bank’s security system was resistant to penetration, but Cobalt took advantage of contemporary business features, namely the dependence on various contractors, the perimeter of which is weaker.”
 

Tags: CybersecurityTechnology
ShareTweet
Previous Post

Ontrack publishes Top 10 DIY Data Recovery Fails

Next Post

Longer, Expanding, Demanding: Botnet DDoS Attacks Highlighted in Kaspersky Lab Quarterly Report

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol