APT Intelligence Directory
Institute for Critical Infrastructure Cybersecurity
RU

Cobalt Group

High ConfidenceHigh Threat

Cobalt Gang • Cobalt Spider • GOLD KINGSWOOD

Cobalt Group is a financially motivated threat actor that has been active since at least 2016, primarily targeting financial institutions worldwide. The group gained notoriety for attacks against ATM networks, SWIFT systems, and payment card processing infrastructure. Cobalt Group's operations have resulted in over $1 billion in attempted thefts from banks across Europe, Asia, and the Americas. Despite the 2018 arrest of their alleged leader in Spain, the group's operations have continued under various guises.

Origin: Russia
Sponsor: Cybercriminal (No State Sponsor)
Active: 2016 - Present
Victims: 100+ financial institutions
Advanced
Active
Financial Gain
Risk Assessment
75
Composite Risk Score
High Risk
ARCS Compliance78
Escalation Risk75
Grievance Index65
Infrastructure Impact80
History & Evolution

Cobalt Group is a financially motivated threat actor that has been active since at least 2016, primarily targeting financial institutions worldwide. The group gained notoriety for attacks against ATM networks, SWIFT systems, and payment card processing infrastructure. Cobalt Group's operations have resulted in over $1 billion in attempted thefts from banks across Europe, Asia, and the Americas. Despite the 2018 arrest of their alleged leader in Spain, the group's operations have continued under various guises.

Targeting

Target Sectors

Financial ServicesBanksATM Networks

Target Regions

EuropeAsiaCIS Countries
Attribution & Affiliations

Attributed to Cybercriminal (No State Sponsor) (Russia). Attribution confidence: High.

Intelligence Assessment
High
Threat Level
Moderately
Targeting
Moderately
Adaptability
High
Persistence
Continuous
Op Tempo
Active
Status

Future Outlook

Cobalt Group is expected to continue operations targeting Financial Services sectors.

Timeline of Key Events
2016
Major

First observed activity of Cobalt Group

2024
Moderate

Continued active operations