PowerDuke is a Windows backdoor associated with APT29, also known as The Dukes, and was observed in operations during 2016. It is designed for post-compromise espionage and host control, providing operators with commands to collect system and user information, inspect running processes, manipulate files, and retrieve additional payloads. Documented reconnaissance functions include enumerating the current user and SID, domain and NetBIOS information, process listings, and system time and time zone details. PowerDuke also supports destructive cleanup actions such as overwriting file contents with random data before deletion.
The malware employs multiple defense-evasion and persistence mechanisms. It has been documented hiding backdoor payloads in NTFS alternate data streams and using rundll32.exe for execution. Persistence has been established through Windows Registry Run keys. Campaign reporting tied PowerDuke delivery to malicious documents with macros, and related lures also included password-protected compressed or encrypted files requiring user interaction to access the payload. PowerDuke is part of APT29’s espionage toolset and aligns with that group’s long-running targeting of government, diplomatic, and other strategically significant organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This method of executing code is often used by APT29 and APT32, software like PowerDuke
This method of executing code is often used by APT29 and APT32, software like PowerDuke
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Command and Scripting Interpreter (T1059): APT29 uses PowerShell and other scripting languages for executing commands.
This shortcut file contains PowerShell commands that conduct anti-VM checks, drop a backdoor, and launch a clean decoy document.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
Sometimes a user's action may be required to open and Deobfuscate/Decode Files or Information for User Execution.
Inside of this password (8734) protected ZIP file is an executable named: RWP16-038_Norris.exe | Inside of this password protected ZIP file is a Microsoft shortcut file (.LNK)... This shortcut file contains PowerShell commands that conduct anti-VM checks, drop a backdoor, and launch a clean decoy document.
Across the content, malware repeatedly 'adds Registry Run keys', 'creates Registry entries', 'modifies the Windows Registry', or 'overwrites registry keys' to maintain persistence.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
Sometimes a user's action may be required to open and Deobfuscate/Decode Files or Information for User Execution.
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
55 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A feature-rich backdoor used for system control and detailed information gathering, extending anti-VM measures from initial droppers.
PowerDuke is mentioned as an example of malware associated with the alternate data streams technique for hiding or executing malicious code.
Backdoor with commands to retrieve the current user's name and SID.
Retrieves victim domain and NetBIOS name.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.