Tracking MiniDionis: CozyCar’s New Ride Is Related to Seaduke - Palo Alto Networks BlogPalo Alto Networks Blog
ID: 212e064b-055a-487d-b777-a5d89d478e38
STIX ID: report--212e064b-055a-487d-b777-a5d89d478e38
Threat Score
78/100
Uploaded: 2026-08-21
Published Date: 2015-07-22
Last Modified Date: 2015-07-22
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 details a CozyDuke/CozyCar campaign that uses the miniDionis malware, delivered through spearphishing and compromised websites, including decoy media and staged payloads, to beacon to a C2 server with RC4-encrypted cookies and network-communication techniques; the report provides IoCs, cryptographic details, and analysis of the malware's structure, commands, and potential impact on government and think-tank targets.
