PowerDuke

S0139

Malware.View on attack.mitre.org

About this malware

PowerDuke is a backdoor that was used by APT29 in 2016. It has primarily been delivered through Microsoft Word or Excel attachments containing malicious macros.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1010
Application Window Discovery

PowerDuke has a command to get text of the current foreground window.

T1016
System Network Configuration Discovery

PowerDuke has a command to get the victim's domain and NetBIOS name.

T1027.003
Steganography

PowerDuke uses steganography to hide backdoors in PNG files, which are also encrypted using the Tiny Encryption Algorithm (TEA).

T1033
System Owner/User Discovery

PowerDuke has commands to get the current user's name and SID.

T1057
Process Discovery

PowerDuke has a command to list the victim's processes.

T1059.003
Windows Command Shell

PowerDuke runs cmd.exe /c and sends the output to its C2.

T1070.004
File Deletion

PowerDuke has a command to write random data across a file and delete it.

T1082
System Information Discovery

PowerDuke has commands to get information about the victim's name, build, version, serial number, and memory usage.

T1083
File and Directory Discovery

PowerDuke has commands to get the current directory name as well as the size of a file. It also has commands to obtain information about logical drives, drive type, and free space.

T1105
Ingress Tool Transfer

PowerDuke has a command to download a file.

T1124
System Time Discovery

PowerDuke has commands to get the time the machine was built, the time, and the time zone.

T1218.011
Rundll32

PowerDuke uses rundll32.exe to load.

T1485
Data Destruction

PowerDuke has a command to write random data across a file and delete it.

T1547.001
Registry Run Keys / Startup Folder

PowerDuke achieves persistence by using various Registry Run keys.

T1564.004
NTFS File Attributes

PowerDuke hides many of its backdoor payloads in an alternate data stream (ADS).

Groups that use it1

Campaigns0

None recorded.

References1

  1. Volexity PowerDuke November 2016 Open source
    Adair, S.. (2016, November 9). PowerDuke: Widespread Post-Election Spear Phishing Campaigns Targeting Think Tanks and NGOs. Retrieved January 11, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.