← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Duke APT group's latest tools: cloud services and Linux support
Recent weeks have seen the outing of two new additions to the Duke group's toolset, SeaDuke and CloudDuke. Of these, SeaDuke is a simple trojan made interesting by the fact that it's written in Python. And even more curiously, SeaDuke, with its built-in support for both Windows and Linux, is the first cross-platform malware we have observed from the Duke group. While SeaDuke is a single - albeit cross-platform - trojan, CloudDuke appears to be an entire toolset of malware components, or "solutions" as the Duke group apparently calls them. These components include a unique loader, downloader, and not one but two different trojan components. CloudDuke also greatly expands on the Duke group's usage of cloud storage services, specifically Microsoft's OneDrive, as a channel for both command and control as well as the exfiltration of stolen data. Finally, some of the recent CloudDuke spear-phishing campaigns have born a striking resemblance to CozyDuke spear-phishing campaigns from a year ago.
Indicators of Compromise (6 / 44 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| YARA | 0a301a6448ff1a2af33b6b9aed7145d47cab172f | — | 2017-07-24 | |
| YARA | 0c6f5e93f51550d08546d1988a98b3ae69fbc379 | — | 2017-07-24 | |
| YARA | 1cb3f2f549f653336273b4bce3403e8c541cf556 | — | 2017-07-24 | |
| YARA | b670db96a4d4ac687063bbcebc089ca3a4045bc6 | — | 2017-07-24 | |
| YARA | fd93a24a91e522d4aa3f1436a8400d5e6a5111f5 | — | 2017-07-24 | |
| YARA | 0c4f4af0bb1fb309c83b98042d62676f14f2f9d1 | — | 2017-07-24 |
References (1)