COBALT JUNOCOBALT JUNO

Also known as: APT-C-38 (QiAnXin) · SABER LION · TG-2884 (SCWX CTU) · COBALT JUNO

Known aliases
4

Profile

COBALT JUNO has operated since at least 2013 and focused on targets located in the Middle East including Iran, Jordan, Egypt & Lebanon. COBALT JUNO custom spyware families SABER1 and SABER2, include surveillance functionality and masquerade as legitimate software utilities such as Adobe Updater, StickyNote and ASKDownloader. CTU researchers assess with moderate confidence that COBALT JUNO operated the ZooPark Android spyware since at least mid-2015. ZooPark was publicly exposed in 2018 in both vendor reporting and a high profile leak of C2 server data. COBALT JUNO is linked to a private security company in Iran and outsources aspects of tool development work to commercial software developers. CTU researchers have observed the group using strategic web compromises to deliver malware. CTU researchers’ discovery of new C2 domains in 2019 suggest the group is still actively performing operations.

Aliases· 4

APT-C-38 (QiAnXin)SABER LIONTG-2884 (SCWX CTU)COBALT JUNO

References

  1. https://www.secureworks.com/research/threat-profiles/cobalt-juno

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
ZooPark
Actor
COBALT KATANA
Actor
APT39
Actor
APT-C-27
Actor
APT33
Actor
AridViper
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.