ATT&CKReferencesF-Secure The Dukes

F-Secure The Dukes

F-Secure Labs. (2015, September 17). The Dukes: 7 years of Russian cyberespionage. Retrieved December 10, 2015.

Open the source

Techniques1

Groups1

Software9

Campaigns0

None recorded.

Procedure examples35

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
MalwareOnionDuke

OnionDuke steals credentials from its victims.

T1003
OS Credential Dumping
MalwarePinchDuke

PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated many sources such as WinInet Credential Cache, and Lightweight Directory Access Protocol (LDAP).

T1003.002
Security Account Manager
MalwareCosmicDuke

CosmicDuke collects Windows account hashes.

T1003.004
LSA Secrets
MalwareCosmicDuke

CosmicDuke collects LSA secrets.

T1005
Data from Local System
MalwarePinchDuke

PinchDuke collects user files from the compromised host based on predefined file extensions.

T1007
System Service Discovery
MalwareGeminiDuke

GeminiDuke collects information on programs and services on the victim that are configured to automatically run at startup.

T1016
System Network Configuration Discovery
MalwareGeminiDuke

GeminiDuke collects information on network settings and Internet proxy settings from the victim.

T1056.001
Keylogging
MalwareCosmicDuke

CosmicDuke uses a keylogger.

T1057
Process Discovery
MalwareGeminiDuke

GeminiDuke collects information on running processes and environment variables from the victim.

T1068
Exploitation for Privilege Escalation
MalwareCosmicDuke

CosmicDuke attempts to exploit privilege escalation vulnerabilities CVE-2010-0232 or CVE-2010-4398.

T1071.001
Web Protocols
MalwareOnionDuke

OnionDuke uses HTTP and HTTPS for C2.

T1071.001
Web Protocols
MalwareCloudDuke

One variant of CloudDuke uses HTTP and HTTPS for C2.

T1071.001
Web Protocols
MalwareCosmicDuke

CosmicDuke can use HTTP or HTTPS for command and control to hard-coded C2 servers.

T1071.001
Web Protocols
MalwareMiniDuke

MiniDuke uses HTTP and HTTPS for command and control.

T1071.001
Web Protocols
MalwareGeminiDuke

GeminiDuke uses HTTP and HTTPS for command and control.

T1071.001
Web Protocols
MalwareSeaDuke

SeaDuke uses HTTP and HTTPS for C2.

T1071.001
Web Protocols
MalwarePinchDuke

PinchDuke transfers files from the compromised host via HTTP or HTTPS to a C2 server.

T1082
System Information Discovery
MalwarePinchDuke

PinchDuke gathers system configuration information.

T1083
File and Directory Discovery
MalwareGeminiDuke

GeminiDuke collects information from the victim, including installed drivers, programs previously executed by users, programs and services configured to automatically run at startup, files and folders present in any user's home folder, files and folders present in any user's My Documents, programs installed to the Program Files folder, and recently accessed files, folders, and programs.

T1083
File and Directory Discovery
MalwarePinchDuke

PinchDuke searches for files created within a certain timeframe and whose file extension matches a predefined list.

T1087.001
Local Account
MalwareGeminiDuke

GeminiDuke collects information on local user accounts from the victim.

T1102.001
Dead Drop Resolver
MalwareMiniDuke

Some MiniDuke components use Twitter to initially obtain the address of a C2 server or as a backup if no hard-coded C2 server responds.

T1102.002
Bidirectional Communication
MalwareCloudDuke

One variant of CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data with its operators.

T1102.003
One-Way Communication
MalwareOnionDuke

OnionDuke uses Twitter as a backup C2.

T1105
Ingress Tool Transfer
GroupAPT29

APT29 has downloaded additional tools and malware onto compromised networks.

T1105
Ingress Tool Transfer
MalwareCloudDuke

CloudDuke downloads and executes additional malware from either a Web address or a Microsoft OneDrive account.

T1203
Exploitation for Client Execution
GroupAPT29

APT29 has used multiple software exploits for common client software, like Microsoft Word, Exchange, and Adobe Reader, to gain code execution.

T1204.002
Malicious File
GroupAPT29

APT29 has used various forms of spearphishing attempting to get a user to open attachments, including, but not limited to, malicious Microsoft Word documents, .pdf, and .lnk files.

T1555
Credentials from Password Stores
MalwarePinchDuke

PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated with many sources such as The Bat!, Yahoo!, Mail.ru, Passport.Net, Google Talk, and Microsoft Outlook.

T1555
Credentials from Password Stores
MalwareCosmicDuke

CosmicDuke collects user credentials, including passwords, for various programs including popular instant messaging applications and email clients as well as WLAN keys.

T1555.003
Credentials from Web Browsers
MalwarePinchDuke

PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated with many sources such as Netscape Navigator, Mozilla Firefox, Mozilla Thunderbird, and Internet Explorer.

T1555.003
Credentials from Web Browsers
MalwareCosmicDuke

CosmicDuke collects user credentials, including passwords, for various programs including Web browsers.

T1566.001
Spearphishing Attachment
GroupAPT29

APT29 has used spearphishing emails with an attachment to deliver files with exploits to initial victims.

T1587.001
Malware
GroupAPT29

APT29 has used unique malware in many of their operations.

T1588.002
Tool
GroupAPT29

APT29 has obtained and used a variety of tools including Mimikatz, SDelete, Tor, meek, and Cobalt Strike.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.