CozyCar

S0046

Malware.View on attack.mitre.org

About this malware

CozyCar is malware that was used by APT29 from 2010 to 2015. It is a modular malware platform, and its backdoor component can be instructed to download and execute a variety of modules with different functionality.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1003.001
LSASS Memory

CozyCar has executed Mimikatz to harvest stored credentials from the victim and further victim penetration.

T1003.002
Security Account Manager

Password stealer and NTLM stealer modules in CozyCar harvest stored credentials from the victim, including credentials used as part of Windows NTLM user authentication.

T1027.013
Encrypted/Encoded File

The payload of CozyCar is encrypted with simple XOR with a rotating key. The CozyCar configuration file has been encrypted with RC4 keys.

T1036.003
Rename Legitimate Utilities

The CozyCar dropper has masqueraded a copy of the infected system's rundll32.exe executable that was moved to the malware's install directory and renamed according to a predefined configuration file.

T1053.005
Scheduled Task

One persistence mechanism used by CozyCar is to register itself as a scheduled task.

T1059.003
Windows Command Shell

A module in CozyCar allows arbitrary commands to be executed by invoking C:\Windows\System32\cmd.exe.

T1071.001
Web Protocols

CozyCar's main method of communicating with its C2 servers is using HTTP or HTTPS.

T1082
System Information Discovery

A system info module in CozyCar gathers information on the victim host’s configuration.

T1102.002
Bidirectional Communication

CozyCar uses Twitter as a backup C2 channel to Twitter accounts specified in its configuration file.

T1218.011
Rundll32

The CozyCar dropper copies the system file rundll32.exe to the install location for the malware, then uses the copy of rundll32.exe to load and execute the main CozyCar component.

T1497
Virtualization/Sandbox Evasion

Some versions of CozyCar will check to ensure it is not being executed inside a virtual machine or a known malware analysis sandbox environment. If it detects that it is, it will exit.

T1518.001
Security Software Discovery

The main CozyCar dropper checks whether the victim has an anti-virus product installed. If the installed product is on a predetermined list, the dropper will exit.

T1543.003
Windows Service

One persistence mechanism used by CozyCar is to register itself as a Windows service.

T1547.001
Registry Run Keys / Startup Folder

One persistence mechanism used by CozyCar is to set itself to be executed at system startup by adding a Registry value under one of the following Registry keys: <br>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ <br>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ <br>HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run <br>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

Groups that use it1

Campaigns0

None recorded.

References1

  1. F-Secure The Dukes Open source
    F-Secure Labs. (2015, September 17). The Dukes: 7 years of Russian cyberespionage. Retrieved December 10, 2015.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.