OnionDuke

S0052

Malware.View on attack.mitre.org

About this malware

OnionDuke is malware that was used by APT29 from 2013 to 2015.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1003
OS Credential Dumping

OnionDuke steals credentials from its victims.

T1071.001
Web Protocols

OnionDuke uses HTTP and HTTPS for C2.

T1102.003
One-Way Communication

OnionDuke uses Twitter as a backup C2.

T1140
Deobfuscate/Decode Files or Information

OnionDuke can use a custom decryption algorithm to decrypt strings.

T1499
Endpoint Denial of Service

OnionDuke has the capability to use a Denial of Service module.

Groups that use it1

Campaigns0

None recorded.

References1

  1. F-Secure The Dukes Open source
    F-Secure Labs. (2015, September 17). The Dukes: 7 years of Russian cyberespionage. Retrieved December 10, 2015.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.