← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Duke APT group's latest tools: cloud services and Linux support
Recent weeks have seen the outing of two new additions to the Duke group's toolset, SeaDuke and CloudDuke. Of these, SeaDuke is a simple trojan made interesting by the fact that it's written in Python. And even more curiously, SeaDuke, with its built-in support for both Windows and Linux, is the first cross-platform malware we have observed from the Duke group. While SeaDuke is a single - albeit cross-platform - trojan, CloudDuke appears to be an entire toolset of malware components, or "solutions" as the Duke group apparently calls them. These components include a unique loader, downloader, and not one but two different trojan components. CloudDuke also greatly expands on the Duke group's usage of cloud storage services, specifically Microsoft's OneDrive, as a channel for both command and control as well as the exfiltration of stolen data. Finally, some of the recent CloudDuke spear-phishing campaigns have born a striking resemblance to CozyDuke spear-phishing campaigns from a year ago.
Indicators of Compromise (7 / 44 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| URL | https://cognimuse.cs.ntua.gr/search.php | — | 2015-07-22 | |
| URL | http://www.recordsmanagementservices.com/eFax/incoming/150721/5442.ZIP | — | 2015-07-22 | |
| URL | http://files.counseling.org/eFax/incoming/150721/5442.ZIP | — | 2015-07-22 | |
| URL | http://flockfilmseries.com/eFax/incoming/5442.ZIP | — | 2015-07-22 | |
| URL | https://97.75.120.45/news/archive.php | — | 2015-07-22 | |
| URL | https://58.80.109.59/plugins/search.php | — | 2015-07-22 | |
| URL | https://portal.sbn.co.th/rss.php | — | 2015-07-22 |
References (1)