OnionDuke is a Windows malware family associated with the Dukes espionage cluster, also known as APT29 or Cozy Bear, and has been publicly linked to Russian intelligence activity. It has been described as a modular toolset comprising at least a dropper, a loader, an information-stealing component, and additional variants and modules. The malware is notable for being distributed through compromised Tor infrastructure, where it acted as a wrapper around legitimate software: victims downloading software through infected Tor nodes could receive trojanized packages that preserved the expected benign program while adding a malicious stub. When executed, the stub could install additional malware, unpack and launch the legitimate software to reduce suspicion, and in some cases remove itself afterward to limit forensic visibility.
OnionDuke supports credential theft and has been reported to steal credentials from compromised victims. It also uses HTTP and HTTPS for command-and-control communications, and reporting has noted a backup command-and-control mechanism using Twitter. Some descriptions also attribute a denial-of-service module to the malware. Technical reporting has highlighted custom decryption or encryption routines used to protect strings and internal data, consistent with the broader Dukes ecosystem’s emphasis on obfuscation and stealth.
The malware has been observed in the broader Dukes operational ecosystem alongside families such as MiniDuke, CozyDuke, CosmicDuke, SeaDuke, HammerDuke, PinchDuke, GeminiDuke, and CloudDuke. Known victimology tied to Dukes operations involving OnionDuke and related tooling includes diplomatic and government targets, particularly ministries of foreign affairs and embassies. OnionDuke is best understood as both a downloader-style delivery mechanism and a credential-stealing espionage implant within a long-running Russian state-linked intrusion set.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PolyglotDuke (SHA-1: D09C4E7B641F8CB7CC86190FD9A778C6955FEA28) uses a custom encryption algorithm to decrypt the strings used by the malware. We found functionally equivalent code in an OnionDuke sample.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Most of the time, the user gets infected by using some unauthenticated online resources. Infections are often consequences of activities like: Clicking malicious links or visiting shady websites Downloading unknown free programs Opening attachments sent with spam Plugging infected drives
An interesting example of a modern downloader is OnionDuke ... It is a wrapper over legitimate software. When a user downloads software via an infected Tor proxy, OnionDuke packs the original file and adds a malicious stub to it.
APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims... BlackByte used tools such as Cobalt Strike and Mimikatz to dump credentials from victim systems... Storm-0501 has used the SecretsDump module within Impacket can perform credential dumping to obtain account and password information.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular toolset including dropper, loader, and information-stealing components, reportedly distributed through a compromised Tor exit node.
OnionDuke is a backdoor malware used by APT29/Cozy Bear for cyber espionage.
OnionDuke is a backdoor malware used by APT29/Cozy Bear for cyber espionage.
OnionDuke is a downloader carried by infected Tor nodes that wraps legitimate software with a malicious stub; when executed, it downloads and installs malware, then unpacks the legitimate file and removes itself to avoid notice.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.