logo

Tracking MiniDionis: CozyCar’s New Ride Is Related to Seaduke - Palo Alto Networks BlogPalo Alto Networks Blog

ID: 212e064b-055a-487d-b777-a5d89d478e38

STIX ID: report--212e064b-055a-487d-b777-a5d89d478e38

Threat Score

78/100

Uploaded: 2026-08-21

Published Date: 2015-07-22

Last Modified Date: 2015-07-22

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 details a CozyDuke/CozyCar campaign that uses the miniDionis malware, delivered through spearphishing and compromised websites, including decoy media and staged payloads, to beacon to a C2 server with RC4-encrypted cookies and network-communication techniques; the report provides IoCs, cryptographic details, and analysis of the malware's structure, commands, and potential impact on government and think-tank targets.