What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Yes—MITRE ATT&CK records Cobalt Group compromising legitimate web browser updates to deliver a backdoor. But that record does not establish that the group has only recently adopted supply-chain attacks, or identify the browser, date, or complete attack chain. Here, “Cobalt hackers” means Cobalt Group, not the Cobalt Strike tool or the cybersecurity company Cobalt.
What is documented about Cobalt Group?
MITRE ATT&CK identifies Cobalt Group as a financially motivated threat group associated primarily with attacks on financial institutions since at least 2016. The profile also lists the names GOLD KINGSWOOD, Cobalt Gang, and Cobalt Spider. Its documented software supply-chain example is a compromise of legitimate web browser updates to deliver a backdoor. MITRE ATT&CK’s Cobalt Group profile does not name the browser or provide the precise date or full delivery chain, so those details cannot be confirmed from that record.
The profile supports saying that Cobalt Group has a recorded supply-chain technique. It does not support the headline’s “now” as a timeline: the available record does not establish when the group began using this approach or that it is a new tactic. MITRE’s profile was last modified on 31 July 2026, but that modification date is not the date of the browser-update incident.
What a supply-chain attack means
A software supply-chain attack compromises a trusted route by which software reaches users. Rather than directly breaking into every downstream organization, an attacker may tamper with a vendor’s development process, a software build, an update, or a dependency. Customers can then receive malicious code through software or packages they believe are legitimate.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
In the browser-update incident recorded by MITRE, the relevant trust path was legitimate updates: the compromised update mechanism was used to deliver a backdoor. The profile does not provide enough detail to describe how the compromise was introduced or what happened after delivery.
Three different “Cobalts” that should not be conflated
| Name | What it refers to | What an incident involving it establishes |
|---|---|---|
| Cobalt Group | A financially motivated threat group; MITRE lists GOLD KINGSWOOD, Cobalt Gang, and Cobalt Spider as associated names. | An actor attribution, when a source specifically connects the activity to the group. MITRE records its browser-update compromise. |
| Cobalt Strike | A commercial security tool designed for authorized security testing and attack simulation, which criminals have also abused. | The tool’s presence alone does not identify the operator as Cobalt Group. |
| Cobalt | A cybersecurity company that disclosed limited exposure of secondary repositories to the Shai-Hulud npm campaign in November 2025. | A company’s account of its own incident, not evidence of Cobalt Group activity. |
Europol described Cobalt Strike as “designed to help legitimate IT security experts perform attack simulations that identify weaknesses in security operations and incident responses.” Its legitimate use and criminal abuse are both possible; neither makes the tool synonymous with Cobalt Group. Europol’s 3 July 2024 announcement concerned action against criminal abuse of the tool, not a measure of Cobalt Group’s supply-chain activity.
In Operation MORPHEUS, Europol reported that 690 IP addresses were flagged and 593 taken down in 2024. Those figures describe that operation targeting illegal versions of Cobalt Strike; they are not counts of Cobalt Group attacks or supply-chain compromises.
Why SolarWinds is useful context—and not a Cobalt Group attribution
The SolarWinds Orion campaign illustrates how a compromised vendor build can reach customers through a routine update. The Canadian Centre for Cyber Security says malicious code entered the development environment and that “The compromised build was pushed to customers as an update to their existing Orion installations, deploying SUNBURST into customer environments.” The Centre attributes the SolarWinds campaign to Russia’s SVR; its discussion of Cobalt Strike concerns follow-on tooling, not Cobalt Group. Read the Canadian Centre’s supply-chain guidance.
Rank #3
The Centre says upwards of 18,000 of approximately 300,000 SolarWinds customers were vulnerable, and that at least 200 organizations were identified as subject to targeted follow-on activity. These are figures reported by the Canadian Centre for this SolarWinds incident, not statistics about Cobalt Group. The consulted guidance page does not establish a publication date for these figures.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What Cobalt’s Shai-Hulud disclosure says
In a disclosure dated 24 November 2025, cybersecurity company Cobalt said secondary repositories had limited exposure to the Shai-Hulud npm supply-chain campaign. The company said its investigation found no evidence that customer data, customer environments, or production systems were accessed or impacted. Cobalt’s security update concerns the company’s repositories and its investigation; it does not attribute the campaign to Cobalt Group.
Quick Recap
Best Value
Rank #4
How to read claims about “Cobalt hackers”
- Check whether the report names Cobalt Group as the attributed actor, or is merely discussing Cobalt Strike as a tool.
- Look for a stated basis for attribution; a tool name or the word “Cobalt” is not enough to identify an operator.
- For a supply-chain claim, distinguish a documented compromise of an update or software process from a general report that an attacker used malware after delivery.
- Keep each incident’s scope attached to it: MITRE’s browser-update record, SolarWinds’ Orion compromise, Europol’s Cobalt Strike operation, and Cobalt company’s Shai-Hulud disclosure describe different events.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

