Cobalt Mirage
Named by SecureWorksSuspected state sponsor: Islamic Republic of IranCobalt Mirage is Secureworks' designation for the Iranian IRGC-linked threat cluster known as Nemesis Kitten. Active since at least 2020, Cobalt Mirage exploits public-facing vulnerabilities in enterprise systems for initial access, then pursues a dual mission of ransomware deployment for financial gain and targeted espionage for intelligence collection. Secureworks documented two distinct operational subgroups within Cobalt Mirage — one focused on broad opportunistic ransomware deployment and one on targeted intelligence collection — sharing the same underlying Iranian organizational structure and initial access infrastructure.
Targeted Regions
AustraliaAustralia
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
EuropeEurope
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
IsraelIsrael
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
United StatesUnited States
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022
Jun 2020 ~ May 2022 Feb 2022 ~ Dec 2022
Jun 2020 ~ May 2022 Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
Feb 2022 ~ Dec 2022
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.