PULSE NAME
Duke APT group's latest tools: cloud services and Linux support
WHITE APT 29 AlienVault 2015-07-22 Modified: 2017-07-24
44
IOCs
MEDIUM VOLUME
Recent weeks have seen the outing of two new additions to the Duke group's toolset, SeaDuke and CloudDuke. Of these, SeaDuke is a simple trojan made interesting by the fact that it's written in Python. And even more curiously, SeaDuke, with its built-in support for both Windows and Linux, is the first cross-platform malware we have observed from the Duke group. While SeaDuke is a single - albeit cross-platform - trojan, CloudDuke appears to be an entire toolset of malware components, or "solutions" as the Duke group apparently calls them. These components include a unique loader, downloader, and not one but two different trojan components. CloudDuke also greatly expands on the Duke group's usage of cloud storage services, specifically Microsoft's OneDrive, as a channel for both command and control as well as the exfiltration of stolen data. Finally, some of the recent CloudDuke spear-phishing campaigns have born a striking resemblance to CozyDuke spear-phishing campaigns from a year ago.
Indicators of Compromise (7 / 44 total)
All URL FileHash-SHA1 YARA FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
URL https://cognimuse.cs.ntua.gr/search.php 2015-07-22
URL http://www.recordsmanagementservices.com/eFax/incoming/150721/5442.ZIP 2015-07-22
URL http://files.counseling.org/eFax/incoming/150721/5442.ZIP 2015-07-22
URL http://flockfilmseries.com/eFax/incoming/5442.ZIP 2015-07-22
URL https://97.75.120.45/news/archive.php 2015-07-22
URL https://58.80.109.59/plugins/search.php 2015-07-22
URL https://portal.sbn.co.th/rss.php 2015-07-22