Minodo

First seen
2023-02-28 00:00:00
Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 14:58:23

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services

Context

Since late February 2023, Minodo Backdoor campaigns have been employed to deliver either the Project Nemesis information stealer or more sophisticated backdoors like Cobalt Strike. This backdoor collects basic system information, which it then transmits to the C2 server. In return, it receives an AES-encrypted payload. Notably, the Minodo Backdoor is designed to contact a different C2 address for domain-joined systems. This suggests that more capable backdoors, such as Cobalt Strike, are downloaded on higher-value targets instead of Project Nemesis.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Domino (report)
  • securityintelligence.com — Ex Conti Fin7 Actors Collaborate New Domino Backdoor (report)

External references