Matryoshka
S0167 · Windows
Matryoshka is a malware framework used by CopyKittens that consists of a dropper, loader, and RAT. It has multiple versions.
v1 was seen in the wild from July 2016 until January 2017. v2 has fewer commands and other minor differences.
ATT&CK S0167
1 actors documented