APT / THREAT GROUP

Cobalt

7
aliases
Last seen:Mar 17, 2026

Intelligence Profile

A criminal group dubbed Cobalt is behind synchronized ATM heists that saw machines across Europe, CIS countries (including Russia), and Malaysia being raided simultaneously, in the span of a few hours. The group has been active since June 2016, and their latest attacks happened in July and August.

Threat Analysis

Cobalt is a known-sophistication threat actor of undetermined national origin, engaged in cyber operations with a primary motivation of unknown activity patterns.

Intelligence Reports Mentioning Cobalt

External References

Quick Facts

TypeAPT / Threat Group
Aliases7
SourceMalpedia

Also Known As

Mule LibraCobalt GroupCobaltCOBALT SPIDERG0080Cobalt GangGOLD KINGSWOOD

Research Links

Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.
Cobalt — APT / Threat Group | Threat Intelligence | CTIWATCH.COM