FatDuke is an advanced Windows backdoor associated with the Dukes espionage platform, also known as APT29 or Cozy Bear, and was used in the long-running Operation Ghost cyberespionage campaign. It served as a later-stage implant in a multi-stage intrusion chain that also included PolyglotDuke, RegDuke, and MiniDuke. The malware is characterized by extensive functionality, flexible configuration, heavy obfuscation, and frequent recompilation intended to hinder detection and analysis.
FatDuke supports post-compromise operations including execution of PowerShell scripts, process enumeration, host profiling, file and directory collection, and encrypted command-and-control communications. Reported host discovery behavior includes identifying the victim system’s MAC address and listing running processes. It can copy files and directories from compromised hosts, indicating use in collection and staging of victim data. Its command-and-control traffic uses AES encryption, and operators have used multiple command-and-control servers per targeted organization to improve resilience and compartmentalization.
The malware also includes persistence and anti-forensics features. It has been observed establishing persistence through Windows Registry Run keys and can securely delete its own DLL component to reduce forensic visibility. Additional functionality includes interacting with the default browser and retrieving browser-related configuration data from the system.
FatDuke has been linked to high-value diplomatic targeting, including ministries of foreign affairs and embassy environments in Europe and Washington, DC, consistent with APT29’s broader intelligence-collection mission against government and diplomatic entities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FatDuke, the third stage. This sophisticated backdoor implements a lot of functionalities and has a very flexible configuration.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Persistence T1053 Scheduled Task The Dukes use Scheduled Task to launch malware at startup.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
Persistence T1053 Scheduled Task The Dukes use Scheduled Task to launch malware at startup.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
Persistence T1053 Scheduled Task The Dukes use Scheduled Task to launch malware at startup.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The Dukes encrypts PolyglotDuke and LiteDuke payloads with custom algorithms. They also rely on known obfuscation techniques such as opaque predicates and control flow flattening to obfuscate RegDuke, MiniDuke and FatDuke.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
Discovery T1049 System Network Connections Discovery The Dukes can execute commands like net use to gather information on network connections.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
Command and Control T1071 Standard Application Layer Protocol The Dukes are using HTTP and HTTPS protocols to communicate with the C&C server.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
43 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An advanced, heavily obfuscated backdoor with flexible configuration designed to evade detection.
Malware capable of executing PowerShell scripts.
Identifies MAC addresses on target computers.
APT29 malware strain used in Operation Ghost.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.