Skip to content

Malware

Covicli

aka Covically

Covicli is a modified SSLeay32 dynamic library designated as a backdoor.

Covicli, also known as Covically, is a Windows malware family operated by MuddyWater.

Background

Covicli is a backdoor implemented as a tampered SSLeay32 dynamic library. Through this library, the attacker is able to communicate with the C2 using openSSL.


Source: Malpedia (Fraunhofer FKIE).