LiteDuke

S0513

Malware.View on attack.mitre.org

About this malware

LiteDuke is a third stage backdoor that was used by APT29, primarily in 2014-2015. LiteDuke used the same dropper as PolyglotDuke, and was found on machines also compromised by MiniDuke.

Techniques used13

Procedure examples13

TechniqueProcedure example
T1012
Query Registry

LiteDuke can query the Registry to check for the presence of HKCU\Software\KasperskyLab.

T1016
System Network Configuration Discovery

LiteDuke has the ability to discover the proxy configuration of Firefox and/or Opera.

T1027.002
Software Packing

LiteDuke has been packed with multiple layers of encryption.

T1027.003
Steganography

LiteDuke has used image files to hide its loader component.

T1033
System Owner/User Discovery

LiteDuke can enumerate the account name on a targeted system.

T1070.004
File Deletion

LiteDuke can securely delete files by first writing random data to the file.

T1071.001
Web Protocols

LiteDuke can use HTTP GET requests in C2 communications.

T1082
System Information Discovery

LiteDuke can enumerate the CPUID and BIOS version on a compromised system.

T1105
Ingress Tool Transfer

LiteDuke has the ability to download files.

T1140
Deobfuscate/Decode Files or Information

LiteDuke has the ability to decrypt and decode multiple layers of obfuscation.

T1497.003
Time Based Checks

LiteDuke can wait 30 seconds before executing additional code if security software is detected.

T1518.001
Security Software Discovery

LiteDuke has the ability to check for the presence of Kaspersky security software.

T1547.001
Registry Run Keys / Startup Folder

LiteDuke can create persistence by adding a shortcut in the CurrentVersion\Run Registry key.

Groups that use it1

Campaigns0

None recorded.

References1

  1. ESET Dukes October 2019 Open source
    Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.