CosmicDuke is an information-stealing malware family associated with The Dukes/APT29 and also referenced under the aliases TinyBaron, BotgenStudios, and NemesisGemina. The toolset is built around a primary information stealer with optional components. Reported capabilities include acting as a keylogger, taking periodic screenshots and exfiltrating them, copying and exfiltrating clipboard contents every 30 seconds, stealing user files, exporting information, and collecting credentials. It steals files from local hard drives, removable media, and network shared drives when file extensions and keywords match a predefined list. It collects credentials, including passwords, from web browsers, instant messaging applications, email clients, WLAN keys, and LSA secrets. For persistence, CosmicDuke has used Windows services typically named "javamtsup" and scheduled tasks typically named "Watchmon Service." It has also been reported to attempt privilege escalation via CVE-2010-0232 or CVE-2010-4398. For command and control, it can use HTTP or HTTPS to hard-coded C2 servers. For exfiltration, it sends collected files over FTP or WebDAV and can use exfiltration servers configured separately from its C2 servers. The content also notes that APT29 used CosmicDuke in a 2014 campaign to steal sensitive information from victims worldwide.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CosmicDuke attempts to exploit privilege escalation vulnerabilities CVE-2010-0232 or CVE-2010-4398.
CosmicDuke attempts to exploit privilege escalation vulnerabilities CVE-2010-0232 or CVE-2010-4398.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CosmicDuke : The CosmicDuke toolset is built around a primary information stealer, enhanced by various optional components.
In 2014, we reported other malware used by “The Dukes”, named CosmicDuke.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
Agent Tesla has the ability to steal credentials from FTP clients and wireless profiles... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the credential vault and DPAPI.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
The content repeatedly describes threat actors and malware collecting, stealing, identifying, copying, or staging files, documents, credentials, logs, databases, and other information from compromised hosts or local systems.
AppleSeed can find and collect data from removable media devices. APT28 backdoor may collect the entire contents of an inserted USB device. Aria-body has the ability to collect data from USB devices. BADNEWS copies files with certain extensions from USB devices to a predefined directory.
“APT28 has collected files from network shared drives… BADNEWS crawls the victim's mapped drives and collects documents… BRONZE BUTLER has exfiltrated files stolen from file shares… menuPass has collected data from remote systems by mounting network shares with net use and using Robocopy to transfer data… Ramsay can collect data from network drives and stage it for exfiltration… Sowbug extracted Word documents from a file server on a victim network.”
"Agent Tesla can capture screenshots of the victim’s desktop"; "AppleSeed can take screenshots on a compromised host"; "APT28 has used tools to take screenshots from victims"; "Cobalt Strike's Beacon payload is capable of capturing screenshots"; "PowerSploit's Get-TimedScreenshot Exfiltration module can take screenshots at regular intervals"; "Hydraq includes a component based on the code of VNC that can stream a live feed of the desktop"
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
Agent Tesla has routines for exfiltration over SMTP, FTP, and HTTP.
Thrip has used WinSCP to exfiltrate data from a targeted organization over FTP.
44 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
CosmicDuke is a modular espionage malware used by APT29 for long-term cyber-espionage campaigns, featuring advanced persistence and stealth capabilities.
An information-stealing malware family with optional persistence and privilege-escalation modules.
CosmicDuke is a backdoor malware used by the APT29/Cozy Bear threat actor for espionage and data exfiltration.
CosmicDuke is a backdoor malware used by the APT29/Cozy Bear threat actor for espionage and data exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.