CozyDuke, also known as CozyCar and Cozer, is a modular Windows malware platform centered on a core backdoor. It is used for cyberespionage by APT29, also known as The Dukes or Cozy Bear, a threat group attributed to Russia’s Foreign Intelligence Service. Documented targets include government and diplomatic organizations, international-policy institutions, and private research organizations in the United States and Europe.
CozyDuke has been distributed through phishing emails using Office Monkeys and eFax themes. It supports harvesting and exfiltrating sensitive information and has executed Mimikatz to obtain victim credentials. Operators have used encoded PowerShell scripts on infected systems to download and execute SeaDuke, deploying that additional implant selectively on targets of particular interest. CozyDuke-infected systems have also been instructed to install MiniDuke.
The malware establishes persistence through scheduled tasks, Windows services, and registry-based startup execution. Its dropper checks installed antivirus products and terminates when specified products are detected. Some versions also detect virtual machines or known malware-analysis sandboxes and exit to avoid analysis. The dropper copies a legitimate Windows DLL-execution utility and uses it to load the main malware component. CozyDuke can use Twitter as a backup command-and-control channel through accounts specified in its configuration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT29 has used encoded PowerShell scripts uploaded to CozyCar installations to download and install SeaDuke.
Seaduke victims are generally first infected with Cozyduke and, if the computer appears to be a target of interest, the operators will install Seaduke.
Seaduke victims are generally first infected with Cozyduke and, if the computer appears to be a target of interest, the operators will install Seaduke.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer. They also replaced the ImagePath registry value of a Windows service with a new backdoor binary.
The content lists additional autostart locations including HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run, HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run, RunServices, and RunServicesOnce.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer. They also replaced the ImagePath registry value of a Windows service with a new backdoor binary.
The content lists additional autostart locations including HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run, HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run, RunServices, and RunServicesOnce.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
44 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
CozyDuke is an espionage malware used by APT29, known for its modularity and use in persistent, stealthy cyber-espionage operations.
A modular malware platform centered on a backdoor that can download and execute additional modules from command-and-control.
CozyDuke is a backdoor malware used by APT29/Cozy Bear for persistent access and espionage.
CozyDuke is a backdoor malware used by APT29/Cozy Bear for persistent access and espionage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.