HAMMERTOSS, also known as HammerDuke and NetDuke, is a stealth-focused backdoor associated with APT29, the Russian state-linked espionage group commonly known as Cozy Bear or The Dukes. It is designed for covert command-and-control and data theft from compromised Windows systems, with tradecraft emphasizing low-observable communications, hidden execution, and abuse of legitimate web services.
The malware is notable for using PowerShell during execution and for concealing PowerShell activity with hidden window parameters to reduce user visibility. Its command-and-control design has been linked to algorithmically generated social media accounts used to publish daily cues, with commands encrypted using a combination of a hard-coded value and data derived from a tweet, then embedded in image files through steganographic techniques. HAMMERTOSS has also used HTTP and HTTPS to retrieve command material and has exfiltrated stolen data by uploading it to actor-controlled accounts on cloud storage providers, allowing operators to blend malicious traffic with normal web activity.
HAMMERTOSS fits APT29’s broader espionage pattern of stealthy persistence, covert collection, and use of legitimate online platforms for operational security. It has been reported as part of the Dukes malware ecosystem alongside families such as MiniDuke, CosmicDuke, CozyDuke, SeaDuke, OnionDuke, and CloudDuke. Its primary role is covert remote access and data theft in intelligence-gathering operations, particularly against targets of strategic interest to Russian intelligence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group’s malware and campaigns include PinchDuke, GeminiDuke, CosmicDuke, MiniDuke, CozyDuke, OnionDuke, SeaDuke, HammerDuke and CloudDuke.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
Many entries describe XOR, XOR/ADD, bitwise NOT and XOR, ROR plus XOR, hexadecimal encoding after encryption, and custom encoding/obfuscation of HTTP traffic or beacons.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
Examples in the content include: 'APT41 used HTTP to download payloads,' 'Cardinal RAT is downloaded using HTTP,' 'Crimson can use a HTTP GET request to download its final payload,' 'CSPY Downloader can use GET requests to download additional payloads,' and 'GuLoader can use HTTP to retrieve additional binaries.'
APT29 has registered algorithmically generated Twitter handles that are used for C2 by malware, such as HAMMERTOSS.
The content is a catalog of malware and threat groups that encrypt command-and-control communications using algorithms such as DES, AES, RC4, XOR, Blowfish, RSA, Camellia, RC2, RC6, and custom ciphers.
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
Kimsuky has exfiltrated stolen files and data to actor-controlled Blogspot accounts. Octopus has exfiltrated data to file sharing sites. HAMMERTOSS exfiltrates data by uploading it to accounts created by the actors on Web cloud storage providers for the adversaries to retrieve later.
Akira will exfiltrate victim data using applications such as Rclone. APT41 DUST exfiltrated collected information to OneDrive. BoomBox can upload data to dedicated per-victim folders in Dropbox. During C0015, the threat actors exfiltrated files and sensitive data to the MEGA cloud storage site using the Rclone command.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware that hides PowerShell windows during execution.
A simple backdoor typically distributed by CozyDuke on already compromised systems.
HammerDuke (aka Hammertoss) is a backdoor malware used by APT29/Cozy Bear for stealthy command and control and espionage.
HammerDuke (aka Hammertoss) is a backdoor malware used by APT29/Cozy Bear for stealthy command and control and espionage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.