Kaspersky reported that the CozyDuke advanced persistent threat conducted targeted intrusions using spearphishing emails and malware-laced documents to compromise victims that included government organizations, diplomatic entities, and other high-profile institutions. The campaign relied on social engineering themes tied to political and security events, with malicious attachments and links delivering backdoors designed to establish persistence, collect system information, and enable follow-on access.
The operation was described as part of a broader espionage effort linked to tools and tactics overlapping with other Duke malware families, indicating a coordinated threat actor with a mature toolkit. Researchers said the malware used stealth and modular functionality to evade detection and maintain long-term access, underscoring the risk posed by state-aligned intrusion sets that blend tailored phishing, custom implants, and quiet data collection against strategic targets.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Securelist published a report titled "The CozyDuke APT," documenting the threat actor and its activity. No additional event details are available from the provided reference content.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.