PULSE NAME
The Dukes aren’t back — they never left
WHITE Dukes AlienVault 2019-10-17 Modified: 2019-10-17
94
IOCs
HIGH VOLUME
It is exceptionally rare for a well-documented threat actor, previously implicated in very high-profile attacks, to stay completely under the radar for several years. Yet, in the last three years that is what APT group the Dukes (aka APT29 and Cozy Bear) has done. Despite being well known as one of the groups to hack the Democratic National Committee in the run-up to the 2016 US election, the Dukes has received little subsequent attention. The last documented campaign attributed to them is a phishing campaign against the Norwegian government that dates back to January 2017
Indicators of Compromise (19 / 94 total)
All domain FileHash-SHA256 URL hostname FileHash-MD5 FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 e4d31bd6bb58cbeafa57f1d2a78cd249 2019-10-17
FileHash-MD5 98b2087f9b842320c39ab041c08fefce 2019-10-17
FileHash-MD5 fc7fbe66c820f17c30147235e95d31b8 2019-10-17
FileHash-MD5 92d2204691f8ac9274b2943f88958552 2019-10-17
FileHash-MD5 1559be5e8b96312f3fbe383c8d810053 2019-10-17
FileHash-MD5 a66a3948fe8fbce7ce8ba88eb9daa0ba 2019-10-17
FileHash-MD5 ffdadc7a09832c7ddf310a07ca65f816 2019-10-17
FileHash-MD5 e2935caf2dd982c918366549fad168ca 2019-10-17
FileHash-MD5 378ae22bbb1ef4b1ac031dccb3094931 2019-10-17
FileHash-MD5 16981cc83348c6f4e6786726eea12054 2019-10-17
FileHash-MD5 79b3bc9f67444f6dee1d8127a0e300ab 2019-10-17
FileHash-MD5 805f4fb534f8665abc74ff00741dd721 2019-10-17
FileHash-MD5 5e08b729bb708530d36b5d3bd1aa08fd 2019-10-17
FileHash-MD5 a6b1ae7b778a9f8994617d4babd7ee85 2019-10-17
FileHash-MD5 d96491796c402a1aebb30b00b20ac8c2 2019-10-17
FileHash-MD5 c8e6cab481e023001ef10dd278ff83c2 2019-10-17
FileHash-MD5 1e599b7cae957c2ce87f95822b9f560a 2019-10-17
FileHash-MD5 cc216e41ad4291d0cc4c77d88c234f6d 2019-10-17
FileHash-MD5 8173ccb6b3936f72bb8701025d92ff7e 2019-10-17