Skip to content

Hide Navigation Hide TOC

Dimnie (9fed4326-a7ad-4c58-ab87-90ac3957d82f)

Dimnie, the commonly agreed upon name for the binary dropped by the PowerShell script above, has been around for several years. Palo Alto Networks has observed samples dating back to early 2014 with identical command and control mechanisms. The malware family serves as a downloader and has a modular design encompassing various information stealing functionalities. Each module is injected into the memory of core Windows processes, further complicating analysis. During its lifespan, it appears to have undergone few changes and its stealthy command and control methods combined with a previously Russian focused target base has allowed it to fly under the radar up until this most recent campaign.

Cluster A Galaxy A Cluster B Galaxy B Level
Dimnie (9fed4326-a7ad-4c58-ab87-90ac3957d82f) Tool Dimnie (8f5ce8a6-c5fe-4c62-b25b-6ce0f3b724c5) Malpedia 1