CozyCar — Malware Profile
CozyCar is malware that was used by APT29 from 2010 to 2015. It is a modular malware platform, and its backdoor component can be instructed to download and execute a variety of modules with different functionality.
MITRE ATT&CK techniques (14)
- T1003.001 LSASS Memory
- T1003.002 Security Account Manager
- T1027.013 Encrypted/Encoded File
- T1036.003 Rename Legitimate Utilities
- T1053.005 Scheduled Task
- T1059.003 Windows Command Shell
- T1071.001 Web Protocols
- T1082 System Information Discovery
- T1102.002 Bidirectional Communication
- T1218.011 Rundll32
- T1497 Virtualization/Sandbox Evasion
- T1518.001 Security Software Discovery
- T1543.003 Windows Service
- T1547.001 Registry Run Keys / Startup Folder