PULSE NAME
THE DUKES: 7 years of Russian cyberespionage
WHITE APT 29 AlienVault 2015-09-17 Modified: 2017-03-06
297
IOCs
HIGH VOLUME
The Dukes are a well-resourced, highly dedicated and organized cyberespionage group that we believe has been working for the Russian Federation since at least 2008 to collect intelligence in support of foreign and security policy decision-making. ...the Dukes show unusual confidence in their ability to continue successfully compromising their targets [...], as well as in their ability to operate with impunity. The Dukes primarily target Western governments and related organizations, such as government ministries and agencies, political think tanks, and governmental subcontractors. Their targets have also included the governments of members of the Commonwealth of Independent States; Asian, African, and Middle Eastern governments; organizations associated with Chechen extremism; and Russian speakers engaged in the illicit trade of controlled substances and drugs.
Indicators of Compromise (4 / 297 total)
All domain hostname FileHash-SHA1 CVE
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2010-0232 2015-09-17
CVE CVE-2010-4398 2015-09-17
CVE CVE-2013-0641 2015-09-17
CVE CVE-2013-0640 2015-09-17