Malware
Minodo
Since late February 2023, Minodo Backdoor campaigns have been employed to deliver either the Project Nemesis information stealer or more sophisticated backdoors like Cobalt Strike.
Minodo is a Windows malware family.
Background
From late February 2023 onward, campaigns using the Minodo Backdoor have served as a delivery mechanism for either the Project Nemesis information stealer or more advanced backdoors such as Cobalt Strike. The backdoor harvests basic system details and sends them to its C2 server, which replies with an AES-encrypted payload. Notably, Minodo reaches out to a separate C2 address when running on domain-joined hosts, implying that higher-value targets receive more capable backdoors like Cobalt Strike rather than Project Nemesis.
Source: Malpedia (Fraunhofer FKIE).