PULSE NAME
Duke APT group's latest tools: cloud services and Linux support
WHITE APT 29 AlienVault 2015-07-22 Modified: 2017-07-24
44
IOCs
MEDIUM VOLUME
Recent weeks have seen the outing of two new additions to the Duke group's toolset, SeaDuke and CloudDuke. Of these, SeaDuke is a simple trojan made interesting by the fact that it's written in Python. And even more curiously, SeaDuke, with its built-in support for both Windows and Linux, is the first cross-platform malware we have observed from the Duke group. While SeaDuke is a single - albeit cross-platform - trojan, CloudDuke appears to be an entire toolset of malware components, or "solutions" as the Duke group apparently calls them. These components include a unique loader, downloader, and not one but two different trojan components. CloudDuke also greatly expands on the Duke group's usage of cloud storage services, specifically Microsoft's OneDrive, as a channel for both command and control as well as the exfiltration of stolen data. Finally, some of the recent CloudDuke spear-phishing campaigns have born a striking resemblance to CozyDuke spear-phishing campaigns from a year ago.
Indicators of Compromise (18 / 44 total)
All URL FileHash-SHA1 YARA FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 bfe26837da22f21451f0416aa9d241f98ff1c0f8 2015-07-22
FileHash-SHA1 52d44e936388b77a0afdb21b099cf83ed6cbaa6f 2015-07-22
FileHash-SHA1 cc15924d37e36060faa405e5fa8f6ca15a3cace2 2015-07-22
FileHash-SHA1 f54f4e46f5f933a96650ca5123a4c41e115a9f61 2015-07-22
FileHash-SHA1 317bde14307d8777d613280546f47dd0ce54f95b 2015-07-22
FileHash-SHA1 78fbdfa6ba2b1e3c8537be48d9efc0c47f417f3c 2015-07-22
FileHash-SHA1 c16529dbc2987be3ac628b9b413106e5749999ed 2015-07-22
FileHash-SHA1 9f5b46ee0591d3f942ccaa9c950a8bff94aa7a0f 2015-07-22
FileHash-SHA1 f97c5e8d018207b1d546501fe2036adfbf774cfd 2015-07-22
FileHash-SHA1 6a3c2ad9919ad09ef6cdffc80940286814a0aa2c 2015-07-22
FileHash-SHA1 04299c0b549d4a46154e0a754dda2bc9e43dff76 2015-07-22
FileHash-SHA1 ed0cf362c0a9de96ce49c841aa55997b4777b326 2015-07-22
FileHash-SHA1 dea6e89e36cf5a4a216e324983cc0b8f6c58eaa8 2015-07-22
FileHash-SHA1 4800d67ea326e6d037198abd3d95f4ed59449313 2015-07-22
FileHash-SHA1 28d29c702fdf3c16f27b33f3e32687dd82185e8b 2015-07-22
FileHash-SHA1 2f53bfcd2016d506674d0a05852318f9e8188ee1 2015-07-22
FileHash-SHA1 e33e6346da14931735e73f544949a57377c6b4a0 2015-07-22
FileHash-SHA1 476099ea132bf16fa96a5f618cb44f87446e3b02 2015-07-22