Cobalt Ulster Spearphishing Operations: A Continued Threat to Governmental Security
- Actor Motivations: Espionage
- Attack Vectors: Brute-force,Downloader,Dropper,Malicious Macro,Malware,RAT,Trojan,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/High Probability
Threat Overview
In a series of espionage-focused campaigns, the Cobalt Ulster threat group, linked to the Iranian government, targeted governmental and intergovernmental organizations across Turkey, Jordan, Iraq, Georgia, and Azerbaijan from mid-2019 to mid-January 2020. These attacks primarily involved spearphishing with malicious attachments and links to compromised websites. The group used various techniques, including obfuscated macros in Excel files, VBScript, and PowerShell scripts for initial access and persistence. The campaigns featured sophisticated methods like DNS tunneling for command and control, and the use of tools for credential harvesting and establishing reverse SSL tunnels, indicating a high level of technical proficiency and strategic planning.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Government Agencies and Services | Verified |
| Region | Azerbaijan | Verified |
| Region | Georgia | Verified |
| Region | Iraq | Verified |
| Region | Jordan | Verified |
| Region | Turkey | Verified |
Extracted IOCs
- advanceorthocenter[.]com
- ampacindustries[.]com
- assignmenthelptoday[.]com
- bing-search[.]ml
- cfm.com[.]pk
- device-update[.]tk
- googlecloud[.]cf
- googlecloud[.]gq
- graphixo[.]net
- ksahosting[.]net
- lalindustries[.]com
- linkupdate[.]org
- msdn-social[.]ml
- msdn-social[.]tk
- officex64[.]ml
- outlook-accounts[.]ml
- outlook-accounts[.]tk
- spacex[.]cf
- spacex[.]gq
- windowscortana[.]tk
- windows-patch[.]ml
- windows-patch[.]tk
- d1ab72db2bedd2f255d35da3da0d4b16
- hxxp://advanceorthocenter[.]com/wp-includes/editor.php?ac=1&n=
- hxxp://cfm.com[.]pk/wp-includes/utf8.php?ac=1&n=
- hxxp://graphixo[.]net/wp-includes/utf8.php?ac=1&n=
- hxxp://ksahosting[.]net/wp-includes/utf8.php
- hxxp://lalindustries[.]com/wp-content/upgrade/editor.php?ac=1&n=
- hxxp://linkupdate[.]org/js/js.php?ac=1&n=
- hxxps://assignmenthelptoday[.]com/wp-includes/utf8.php
Tip: 30 related IOCs (0 IP, 22 domain, 7 URL, 0 email, 1 file hash) to this threat have been found.
Overlaps
Source: Cisco Talos - March 2022
Detection (two cases): advanceorthocenter[.]com, lalindustries[.]com
Source: NetWitness - November 2019
Detection (six cases): hxxp://ksahosting[.]net/wp-includes/utf8.php, hxxps://assignmenthelptoday[.]com/wp-includes/utf8.php, ampacindustries[.]com, assignmenthelptoday[.]com, graphixo[.]net, ksahosting[.]net
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
COBALT ULSTER Cyberespionage Operations
Cybersecurity researchers observed ongoing, espionage-focused spearphishing campaigns. Threat actors used deceptive emails containing malicious links or file attachments to compromise computer networks, deploy specialized tracking software, and install remote access tools.
The campaign is attributed to COBALT ULSTER, a threat group tasked by the Iranian government. This advanced group is also tracked by researchers under several other names, including MuddyWater, Seedworm, TEMP.Zagros, and Static Kitten.
The attacks were focused entirely on cyberespionage, driven by broader, long-term strategic goals rather than immediate retaliation for recent geopolitical events. Once inside a network, the attackers prioritized stealing passwords, testing system access, and establishing secure, hidden channels to maintain persistent control.
The threat actors conducted a sustained series of spearphishing campaigns that spanned from mid-2019 through mid-January 2020. Despite heightened political tensions during this period, the scope of these intelligence-gathering operations continued as "business as usual".
Yes, the campaign deliberately targeted governmental organizations in Turkey, Jordan, and Iraq. The attackers also focused their efforts on global intergovernmental organizations and unknown entities situated in Georgia and Azerbaijan.
The attackers sent fraudulent emails designed to trick recipients into clicking a link or opening a seemingly harmless spreadsheet document. If a user opened the document and approved a prompt to enable its content, hidden scripts secretly ran in the background to compromise the computer and communicate with the attackers' servers.
Governments and intergovernmental organizations handle highly sensitive information related to national security, policy, and international relations. Gathering intelligence from these targets supports the broader, long-term strategic and geopolitical goals of the state-sponsored groups conducting the espionage.
Organizations should rigorously review and update their procedures for preventing, detecting, and responding to cyber threats. Specifically, networks need strong defenses against social engineering, deceptive phishing emails, and password-guessing attacks to prevent attackers from harvesting valid user credentials.
This activity represents a highly targeted issue rather than a random, widespread threat. The attackers specifically selected their victims, primarily regional governments and intergovernmental groups—to fulfill focused intelligence-gathering objectives.