ATT&CKReferencesSymantec Seaduke 2015

Symantec Seaduke 2015

Symantec Security Response. (2015, July 13). “Forkmeiamfamous”: Seaduke, latest weapon in the Duke armory. Retrieved July 22, 2015.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1059.001
PowerShell
MalwareSeaDuke

SeaDuke uses a module to execute Mimikatz with PowerShell to perform Pass the Ticket.

T1059.001
PowerShell
GroupAPT29

APT29 has used encoded PowerShell scripts uploaded to CozyCar installations to download and install SeaDuke.

T1059.006
Python
GroupAPT29

APT29 has developed malware variants written in Python.

T1070.004
File Deletion
MalwareSeaDuke

SeaDuke can securely delete files, including deleting itself from the victim.

T1078
Valid Accounts
MalwareSeaDuke

Some SeaDuke samples have a module to extract email from Microsoft Exchange servers using compromised credentials.

T1114.002
Remote Email Collection
MalwareSeaDuke

Some SeaDuke samples have a module to extract email from Microsoft Exchange servers using compromised credentials.

T1550.003
Pass the Ticket
MalwareSeaDuke

Some SeaDuke samples have a module to use pass the ticket with Kerberos for authentication.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.