Skip to content

Malware

CobInt

aka COOLPANTS

CobInt, is a self-developed backdoor of the Cobalt group.

CobInt, also known as COOLPANTS, is a Windows malware family operated by Cobalt.

Background

CobInt is a backdoor developed in-house by the Cobalt group. Built in a modular fashion, it can gather preliminary reconnaissance about the infected host and capture video of its desktop. Should the operator find the machine worthwhile, the backdoor fetches and runs a CobaltStrike framework stager. Its CRM mailslot module has also been seen being downloaded by ISFB.


Source: Malpedia (Fraunhofer FKIE).