CopyKittens__2015__Minerva_Clearsky_CopyKittens_11-23-15.pdf
ID: b8256b2b-775c-4805-a994-de476da283b2
STIX ID: report--b8256b2b-775c-4805-a994-de476da283b2
Threat Score
75/100
Uploaded: 2026-08-14
Published Date: 2015-11-25
Last Modified Date: 2015-11-25
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Minerva Labs and ClearSky analyze the CopyKittens campaign: a mid-level threat actor using targeted spear-phishing lures to deliver a multi-stage 'Matryoshka' infection (SCR dropper → reflective DLL loader → in-memory RAT). The toolset uses anti-analysis checks (Pafish-derived), reflective DLL injection, runtime API resolution and DNS-based command-and-control/exfiltration to steal Outlook credentials, keylog and capture screens; the report includes persistence methods, evolving TTPs and a comprehensive list of IoCs (domains, IPs, hashes).
