PULSE NAME
The Dukes aren’t back — they never left
WHITE Dukes AlienVault 2019-10-17 Modified: 2019-10-17
94
IOCs
HIGH VOLUME
It is exceptionally rare for a well-documented threat actor, previously implicated in very high-profile attacks, to stay completely under the radar for several years. Yet, in the last three years that is what APT group the Dukes (aka APT29 and Cozy Bear) has done. Despite being well known as one of the groups to hack the Democratic National Committee in the run-up to the 2016 US election, the Dukes has received little subsequent attention. The last documented campaign attributed to them is a phishing campaign against the Norwegian government that dates back to January 2017
Indicators of Compromise (18 / 94 total)
All domain FileHash-SHA256 URL hostname FileHash-MD5 FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 cf14ac569a63df214128f375c12d90e535770395 2019-10-17
FileHash-SHA1 9e96b00e9f7eb94a944269108b9e02d97142eedc 2019-10-17
FileHash-SHA1 6acc0b1230303f8cf46152697d3036d69ea5a849 2019-10-17
FileHash-SHA1 5905c55189c683bc37258aec28e916c41948cd1c 2019-10-17
FileHash-SHA1 170be45669026f3c1fc5ba2d48817dbf950da3f6 2019-10-17
FileHash-SHA1 a88da2dd033775f7abc8d6fb3ad5dd48efbeade1 2019-10-17
FileHash-SHA1 af2b46d4371ce632e2669fea1959ee8af4ec39ce 2019-10-17
FileHash-SHA1 718c2ce6170d6ca505297b41de072d8d3b873456 2019-10-17
FileHash-SHA1 b05caba461000c6ebd8b237f318577e9bccd6047 2019-10-17
FileHash-SHA1 0e25ee58b119dd48b7c9931879294ac3fc433f50 2019-10-17
FileHash-SHA1 0a5a7dd4ad0f2e50f3577f8d43a4c55ddc1d80cf 2019-10-17
FileHash-SHA1 d625c7ce9dc7e56a29ec9a81650280edc6189616 2019-10-17
FileHash-SHA1 539d021cd17d901539a5e1132ecaab7164ed5db5 2019-10-17
FileHash-SHA1 f7fd63c0534d2f717fd5325d4397597c9ee4065f 2019-10-17
FileHash-SHA1 194d8e2ae4c723ce5fe11c4d9cfefbba32dcf766 2019-10-17
FileHash-SHA1 4ba559c403ff3f5cc2571ae0961eaff6cf0a50f6 2019-10-17
FileHash-SHA1 64d6c11fff2c2aadaacee01b294afcc751316176 2019-10-17
FileHash-SHA1 db19171b239ef6de8e83b2926eadc652e74a5afa 2019-10-17