Threats Feed|Cobalt Ulster|Last Updated 06/05/2026|AuthorCertfa Radar|Publish Date26/02/2020

Cobalt Ulster Spearphishing Operations: A Continued Threat to Governmental Security

  • Actor Motivations: Espionage
  • Attack Vectors: Brute-force,Downloader,Dropper,Malicious Macro,Malware,RAT,Trojan,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/High Probability

Threat Overview

In a series of espionage-focused campaigns, the Cobalt Ulster threat group, linked to the Iranian government, targeted governmental and intergovernmental organizations across Turkey, Jordan, Iraq, Georgia, and Azerbaijan from mid-2019 to mid-January 2020. These attacks primarily involved spearphishing with malicious attachments and links to compromised websites. The group used various techniques, including obfuscated macros in Excel files, VBScript, and PowerShell scripts for initial access and persistence. The campaigns featured sophisticated methods like DNS tunneling for command and control, and the use of tools for credential harvesting and establishing reverse SSL tunnels, indicating a high level of technical proficiency and strategic planning.

Detected Targets

TypeDescriptionConfidence
SectorGovernment Agencies and Services
Verified
RegionAzerbaijan
Verified
RegionGeorgia
Verified
RegionIraq
Verified
RegionJordan
Verified
RegionTurkey
Verified

Extracted IOCs

  • advanceorthocenter[.]com
  • ampacindustries[.]com
  • assignmenthelptoday[.]com
  • bing-search[.]ml
  • cfm.com[.]pk
  • device-update[.]tk
  • googlecloud[.]cf
  • googlecloud[.]gq
  • graphixo[.]net
  • ksahosting[.]net
  • lalindustries[.]com
  • linkupdate[.]org
  • msdn-social[.]ml
  • msdn-social[.]tk
  • officex64[.]ml
  • outlook-accounts[.]ml
  • outlook-accounts[.]tk
  • spacex[.]cf
  • spacex[.]gq
  • windowscortana[.]tk
  • windows-patch[.]ml
  • windows-patch[.]tk
  • d1ab72db2bedd2f255d35da3da0d4b16
  • hxxp://advanceorthocenter[.]com/wp-includes/editor.php?ac=1&n=
  • hxxp://cfm.com[.]pk/wp-includes/utf8.php?ac=1&n=
  • hxxp://graphixo[.]net/wp-includes/utf8.php?ac=1&n=
  • hxxp://ksahosting[.]net/wp-includes/utf8.php
  • hxxp://lalindustries[.]com/wp-content/upgrade/editor.php?ac=1&n=
  • hxxp://linkupdate[.]org/js/js.php?ac=1&n=
  • hxxps://assignmenthelptoday[.]com/wp-includes/utf8.php
download

Tip: 30 related IOCs (0 IP, 22 domain, 7 URL, 0 email, 1 file hash) to this threat have been found.

Overlaps

MuddyWaterMuddyWater's Strategic Cyber Campaigns Across Turkey, Armenia, and Pakistan

Source: Cisco Talos - March 2022

Detection (two cases): advanceorthocenter[.]com, lalindustries[.]com

MuddyWaterExcel-Based Macro Attacks: MuddyWater's Evolving Cyber Strategy

Source: NetWitness - November 2019

Detection (six cases): hxxp://ksahosting[.]net/wp-includes/utf8.php, hxxps://assignmenthelptoday[.]com/wp-includes/utf8.php, ampacindustries[.]com, assignmenthelptoday[.]com, graphixo[.]net, ksahosting[.]net

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

COBALT ULSTER Cyberespionage Operations

Cybersecurity researchers observed ongoing, espionage-focused spearphishing campaigns. Threat actors used deceptive emails containing malicious links or file attachments to compromise computer networks, deploy specialized tracking software, and install remote access tools.

The campaign is attributed to COBALT ULSTER, a threat group tasked by the Iranian government. This advanced group is also tracked by researchers under several other names, including MuddyWater, Seedworm, TEMP.Zagros, and Static Kitten.

The attacks were focused entirely on cyberespionage, driven by broader, long-term strategic goals rather than immediate retaliation for recent geopolitical events. Once inside a network, the attackers prioritized stealing passwords, testing system access, and establishing secure, hidden channels to maintain persistent control.

The threat actors conducted a sustained series of spearphishing campaigns that spanned from mid-2019 through mid-January 2020. Despite heightened political tensions during this period, the scope of these intelligence-gathering operations continued as "business as usual".

Yes, the campaign deliberately targeted governmental organizations in Turkey, Jordan, and Iraq. The attackers also focused their efforts on global intergovernmental organizations and unknown entities situated in Georgia and Azerbaijan.

The attackers sent fraudulent emails designed to trick recipients into clicking a link or opening a seemingly harmless spreadsheet document. If a user opened the document and approved a prompt to enable its content, hidden scripts secretly ran in the background to compromise the computer and communicate with the attackers' servers.

Governments and intergovernmental organizations handle highly sensitive information related to national security, policy, and international relations. Gathering intelligence from these targets supports the broader, long-term strategic and geopolitical goals of the state-sponsored groups conducting the espionage.

Organizations should rigorously review and update their procedures for preventing, detecting, and responding to cyber threats. Specifically, networks need strong defenses against social engineering, deceptive phishing emails, and password-guessing attacks to prevent attackers from harvesting valid user credentials.

This activity represents a highly targeted issue rather than a random, widespread threat. The attackers specifically selected their victims, primarily regional governments and intergovernmental groups—to fulfill focused intelligence-gathering objectives.

About Affiliation
Cobalt Ulster
Cobalt Ulster is Secureworks' designation for the Iranian MOIS-linked threat cluster known as MuddyWater. Secureworks documented Cobalt Ulster operations targeting government and telecommunications organizations in the Middle East using PowerShell-based implants and spear phishing lures. The group's consistent MOIS attribution and targeting profile — focused on regional government intelligence collection — aligns precisely with the broader MuddyWater/Seedworm/Mango Sandstorm cluster tracking across the industry.
View Cobalt Ulster's Insights