Skip to content

Malware

COZYDUKE

aka CozyCar · Cozer · CozyBear · EuroAPT

CozyDuke is not simply a malware toolset; rather, it is a modular malware platform formed around a core backdoor component.

COZYDUKE, also known as CozyCar, Cozer, CozyBear, EuroAPT, is a Windows malware family operated by APT29.

Background

Rather than being a mere collection of tools, CozyDuke is a modular malware platform built around a central backdoor component. The C&C server can direct this component to fetch and run arbitrary modules, and these modules are what grant CozyDuke its wide range of capabilities. Documented modules include: • A command execution module for running arbitrary Windows Command Prompt commands • A password stealer module • An NT LAN Manager (NTLM) hash stealer module • A system information gathering module • A screenshot module


Source: Malpedia (Fraunhofer FKIE).