PinchDuke

S0048

Malware.View on attack.mitre.org

About this malware

PinchDuke is malware that was used by APT29 from 2008 to 2010.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1003
OS Credential Dumping

PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated many sources such as WinInet Credential Cache, and Lightweight Directory Access Protocol (LDAP).

T1005
Data from Local System

PinchDuke collects user files from the compromised host based on predefined file extensions.

T1071.001
Web Protocols

PinchDuke transfers files from the compromised host via HTTP or HTTPS to a C2 server.

T1082
System Information Discovery

PinchDuke gathers system configuration information.

T1083
File and Directory Discovery

PinchDuke searches for files created within a certain timeframe and whose file extension matches a predefined list.

T1555
Credentials from Password Stores

PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated with many sources such as The Bat!, Yahoo!, Mail.ru, Passport.Net, Google Talk, and Microsoft Outlook.

T1555.003
Credentials from Web Browsers

PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated with many sources such as Netscape Navigator, Mozilla Firefox, Mozilla Thunderbird, and Internet Explorer.

Groups that use it1

Campaigns0

None recorded.

References1

  1. F-Secure The Dukes Open source
    F-Secure Labs. (2015, September 17). The Dukes: 7 years of Russian cyberespionage. Retrieved December 10, 2015.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.