GeminiDuke is a malware toolset associated with APT29, also known as The Dukes or Cozy Bear, a Russian state-linked cyberespionage group. It is part of the broader Duke malware ecosystem alongside families such as MiniDuke, CosmicDuke, CozyDuke, OnionDuke, SeaDuke, HammerDuke, PinchDuke, and CloudDuke. GeminiDuke has been characterized as featuring a core information-stealing component, a loader, and persistence-related components, indicating a modular design intended to support espionage operations on compromised hosts.
Its observed behavior centers on host reconnaissance and victim profiling. GeminiDuke collects information on local user accounts, running processes, environment variables, network settings, Internet proxy settings, and programs or services configured to automatically run at startup. These capabilities support situational awareness, victim assessment, and preparation for follow-on intrusion activity. GeminiDuke has also been observed using HTTP and HTTPS for command-and-control communications.
The available information supports GeminiDuke as a Windows-focused espionage malware family used in post-compromise phases to gather system and network intelligence and to support persistence within victim environments. No high-confidence evidence in the supplied material establishes a specific initial infection vector for GeminiDuke itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group’s malware and campaigns include PinchDuke, GeminiDuke, CosmicDuke, MiniDuke, CozyDuke, OnionDuke, SeaDuke, HammerDuke and CloudDuke.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
"actors used the following command ... to obtain information about services: net start"; "APT1 used the commands net start and tasklist to get a listing of the services on the system"; "OilRig has used sc query on a victim to gather information about services"; "Indrik Spider has used the win32_service WMI class to retrieve a list of services"
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
GeminiDuke focuses primarily on gathering details about the victim’s computer’s configuration.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A toolset focused on collecting victim system configuration details, with loader and persistence-related components.
GeminiDuke is a backdoor malware used by APT29/Cozy Bear for espionage and persistent access.
GeminiDuke is a backdoor malware used by APT29/Cozy Bear for espionage and persistent access.
Collects network settings and Internet proxy configuration from victims.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.