FatDuke

S0512

Malware.View on attack.mitre.org

About this malware

FatDuke is a backdoor used by APT29 since at least 2016.

Techniques used21

Procedure examples21

TechniqueProcedure example
T1005
Data from Local System

FatDuke can copy files and directories from a compromised host.

T1008
Fallback Channels

FatDuke has used several C2 servers per targeted organization.

T1012
Query Registry

FatDuke can get user agent strings for the default browser from HKCU\Software\Classes\http\shell\open\command.

T1016
System Network Configuration Discovery

FatDuke can identify the MAC address on the target computer.

T1027
Obfuscated Files or Information

FatDuke can use base64 encoding, string stacking, and opaque predicates for obfuscation.

T1027.002
Software Packing

FatDuke has been regularly repacked by its operators to create large binaries and evade detection.

T1027.016
Junk Code Insertion

FatDuke has been packed with junk code and strings.

T1036.012
Browser Fingerprint

FatDuke has attempted to mimic a compromised user's traffic by using the same user agent as the installed browser.

T1057
Process Discovery

FatDuke can list running processes on the localhost.

T1059.001
PowerShell

FatDuke has the ability to execute PowerShell scripts.

T1070.004
File Deletion

FatDuke can secure delete its DLL.

T1071.001
Web Protocols

FatDuke can be controlled via a custom C2 protocol over HTTP.

T1082
System Information Discovery

FatDuke can collect the user name, Windows version, computer name, and available space on discs from a compromised host.

T1083
File and Directory Discovery

FatDuke can enumerate directories on target machines.

T1090.001
Internal Proxy

FatDuke can used pipes to connect machines with restricted internet access to remote machines via other infected hosts.

View all 21 procedure examples

Groups that use it1

Campaigns1

References1

  1. ESET Dukes October 2019 Open source
    Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.