Kaspersky Lab's Global Research and Analysis Team has published research describing a new, advanced digital espionage campaign using malware (CozyDuke) to target very specific and high-ranking actors. 
Targets in the US are believed to include the White House and the State Department, while the list of attackers also includes government agencies and legal entities/commercial entities in Germany, South Korea, and Uzbekistan.
Along with the very precise targeting of high-ranking victims, the threat actor also exhibits other more worrying characteristics.
These include encryption and evasion capabilities. For example, the code “looks” for the presence of security products (from various providers) in order to try to avoid them.
The companies whose products he tries to avoid are Kaspersky Lab, Sophos, DrWeb, Avira, Crystal, and Comodo Dragon.
Connection with other digital espionage actors
Kaspersky Lab experts revealed the malware’s powerful functionality, as well as structural similarities that matched the toolkit used in the MiniDuke, CosmicDuke, and OnionDuke cyberespionage campaigns. According to a number of indicators, the operations are believed to be run by Russian-speaking creators. Kaspersky Lab’s observations show that the MiniDuke and CosmicDuke actors are still active and targeting diplomatic organizations/embassies, energy and hydrocarbon companies, telecommunications providers, military organizations, and academic and research institutions in various countries.
Distribution method
The CozyDuke actor often attacks its targets via spearphishing emails, which contain a link leading to a compromised website (sometimes high-profile, legitimate ones like diplomacy.pl), which hosts a ZIP file containing malware. In other highly successful operations, this actor sends a fake flash video with malicious executable files, included as email attachments.
CozyDuke software uses a backdoor and a dropper. The malware sends information about the target to the Command & Control Server. It also retrieves configuration files and additional modules that perform any additional functionality needed by the attackers.
“We have been monitoring MiniDuke and CosmicDuke for two years. Kaspersky Lab was the first company to warn about MiniDuke attacks in 2013, with the ‘oldest’ known samples of this cyber threat dating back to 2008. CozyDuke is definitely linked to these two campaigns, as well as the cyber espionage activity of OnionDuke. Each of these threat actors continues to monitor their targets, and we believe that all of their espionage tools are created by Russian-speakers,” said Kurt Baumgartner, Principal Security Researcher at Kaspersky Lab’s Global Research and Analysis Team.
Kaspersky Lab products detect all known samples of this threat and protect users.
Tips for users
- Do not open file attachments and links from senders you do not know
- Scan your computer regularly with an advanced anti-malware solution
- Be careful with ZIP files containing SFX files
- If you are unsure about the attached file, try opening it in a sandbox environment
- Make sure you have an up-to-date operating system, with all necessary patches installed
- Update all third-party applications, such as Microsoft Office, Java, Adobe Flash Player, and Adobe Reader
More information about the action of “CozyDuke” is available on the website Securelist.com.
