PULSE NAME
Duke APT group's latest tools: cloud services and Linux support
WHITE APT 29 AlienVault 2015-07-22 Modified: 2017-07-24
44
IOCs
MEDIUM VOLUME
Recent weeks have seen the outing of two new additions to the Duke group's toolset, SeaDuke and CloudDuke. Of these, SeaDuke is a simple trojan made interesting by the fact that it's written in Python. And even more curiously, SeaDuke, with its built-in support for both Windows and Linux, is the first cross-platform malware we have observed from the Duke group. While SeaDuke is a single - albeit cross-platform - trojan, CloudDuke appears to be an entire toolset of malware components, or "solutions" as the Duke group apparently calls them. These components include a unique loader, downloader, and not one but two different trojan components. CloudDuke also greatly expands on the Duke group's usage of cloud storage services, specifically Microsoft's OneDrive, as a channel for both command and control as well as the exfiltration of stolen data. Finally, some of the recent CloudDuke spear-phishing campaigns have born a striking resemblance to CozyDuke spear-phishing campaigns from a year ago.
Indicators of Compromise (6 / 44 total)
All URL FileHash-SHA1 YARA FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
YARA 0a301a6448ff1a2af33b6b9aed7145d47cab172f 2017-07-24
YARA 0c6f5e93f51550d08546d1988a98b3ae69fbc379 2017-07-24
YARA 1cb3f2f549f653336273b4bce3403e8c541cf556 2017-07-24
YARA b670db96a4d4ac687063bbcebc089ca3a4045bc6 2017-07-24
YARA fd93a24a91e522d4aa3f1436a8400d5e6a5111f5 2017-07-24
YARA 0c4f4af0bb1fb309c83b98042d62676f14f2f9d1 2017-07-24