Skip to Content
Iran icon
Iran

COBALT SHADOW

ObjectivesDisruption, Hack and Leak, Ransomware
AliasesAgonizing Serpens (Palo Alto), Agrius, Agrius (SentinelOne), AMERICIUM (Microsoft), BlackShadow, DEV-0227 (Microsoft), Justice Blade (persona), Malek Team, Malek Team (persona), MoneyBird (persona), Pink Sandstorm (Microsoft), Sharp Boyz (persona), Spectral Kitten (Crowdstrike)
ToolsApostle, DEADWOOD, Fantasy wiper, IPsec Helper, MiniDump, Moneybird ransomware, Sandals, SecretsDump

Summary

Since late 2020 COBALT SHADOW has conducted multiple high-profile hack-and-leak attacks against companies in Israel, involving the distribution of personal information. These attacks appear designed to cause political embarrassment by harassing businesses and individuals in Israel, creating a climate of fear and intimidation. This group focuses on targeting a smaller number of victims but maximising the publicity of leaking sensitive information, including medical data. COBALT SHADOW is reported to have engaged in negotiations for extortion payments but frequently increases the demands and publicises the negotiations, likely a tactic to draw out the impact and visibility of their attacks.

COBALT SHADOW use their custom malware, Apostle, to wipe data and perform ransomware style attacks. The group maintains a leak site and has attempted to use multiple personas to offer data for sale in cybercrime forums.
Threat Bottom Section BG

Contact us

Contact us directly whether your organization needs immediate assistance or
you want to discuss your incident readiness, response, and testing needs.