CloudDuke

S0054

Malware.View on attack.mitre.org

About this malware

CloudDuke is malware that was used by APT29 in 2015.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1071.001
Web Protocols

One variant of CloudDuke uses HTTP and HTTPS for C2.

T1102.002
Bidirectional Communication

One variant of CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data with its operators.

T1105
Ingress Tool Transfer

CloudDuke downloads and executes additional malware from either a Web address or a Microsoft OneDrive account.

Groups that use it1

Campaigns0

None recorded.

References2

  1. F-Secure The Dukes Open source
    F-Secure Labs. (2015, September 17). The Dukes: 7 years of Russian cyberespionage. Retrieved December 10, 2015.
  2. Securelist Minidionis July 2015 Open source
    Lozhkin, S.. (2015, July 16). Minidionis – one more APT with a usage of cloud drives. Retrieved April 5, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.