COBALT KATANA targets Kuwait-related organizations using DNS hijacking and a custom Sakabota Framework.
Analyst brief
COBALT KATANA is a threat actor active since at least March 2018, primarily targeting government, logistics, and shipping organizations associated with Kuwait. It gains initial access via DNS hijacking, strategic web compromise using SMB forced authentication, and password brute force attacks. The group leverages a custom Sakabota Framework with modular backdoors like Gon, Hisoka, and Killua, and employs DNS tunnelling in its malware. Defenders should focus on monitoring DNS traffic anomalies, inspecting SMB authentication attempts, and enforcing strong password policies against brute force.
COBALT KATANA has been active since at least March 2018, and it focuses many of its operations on organizations based in or associated with Kuwait. The group has targeted government, logistics, and shipping organizations. The threat actors gain initial access to targets using DNS hijacking, strategic web compromise with SMB forced authentication, and password brute force attacks. COBALT KATANA operates a custom platform referred to as the Sakabota Framework, also referred to as Sakabota Core, with a complimentary set of modular backdoors and accessory tools including Gon, Hisoka, Hisoka Netero, Killua, Diezen, and Eye. The group has implemented DNS tunnelling in its malware and malicious scripts and also operates the HyphenShell web shell to strengthen post-intrusion access. CTU researchers assess with moderate confidence that COBALT KATANA operates on behalf of Iran, and elements of its operations such as overlapping infrastructure, use of DNS hijacking, implementation of DNS-based C2 channels in malware and web shell security mechanisms suggest connections to COBALT GYPSY and COBALT EDGEWATER.
What methods does the COBALT KATANA threat actor use to gain initial access?+
COBALT KATANA gains initial access to targets using DNS hijacking, strategic web compromise with SMB forced authentication, and password brute force attacks.
What custom platform and modular backdoors are used by the COBALT KATANA group?+
The group uses a custom platform called the Sakabota Framework with a complimentary set of modular backdoors including Gon, Hisoka, and Hisoka Netero.