CloudDuke is a malware toolset associated with APT29, also known as Cozy Bear or The Dukes, a Russian intelligence-linked cyberespionage actor. It has been referred to by aliases including CloudLook and MiniDionis. The toolset comprises a loader, a downloader, and backdoor components, including variants known as BastionSolution and OneDriveSolution, indicating a modular design intended to establish access, retrieve additional payloads, and maintain remote control of compromised systems.
CloudDuke is used in espionage operations and functions as a remote access capability within the broader Dukes malware ecosystem, which also includes families such as MiniDuke, CosmicDuke, CozyDuke, OnionDuke, SeaDuke, HammerDuke, PinchDuke, and GeminiDuke. Reported behavior includes command-and-control over HTTP and HTTPS, as well as abuse of Microsoft OneDrive accounts to exchange commands and exfiltrate stolen data. This use of legitimate cloud services helps blend malicious traffic with normal enterprise activity and complicates detection.
The malware has been linked to campaigns targeting government, diplomatic, and other strategically significant organizations consistent with APT29’s long-running intelligence collection mission. Its tradecraft reflects stealth-oriented post-compromise operations, including remote tasking and data theft, rather than disruptive or destructive effects. CloudDuke is best understood as a modular backdoor-centric espionage platform used by APT29 to support covert access and exfiltration in high-value intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group’s malware and campaigns include PinchDuke, GeminiDuke, CosmicDuke, MiniDuke, CozyDuke, OnionDuke, SeaDuke, HammerDuke and CloudDuke.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
APT29 used Cobalt Strike, Silver Red teaming framework, and Zulip for C&C, aligning with their pattern of using legitimate services like Dropbox and OneDrive.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The adversaries had communicated to both Dropbox and Pastebin. APT28 has used Google Drive for C2. APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2.
"APT39 has communicated with C2 through files uploaded to and downloaded from DropBox."; "RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results ... back to Google Drive."; "CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data"
ComRAT has the ability to use the Gmail web UI to receive commands and exfiltrate information. Crutch can use Dropbox to receive commands and upload stolen data. RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results of command execution back to Google Drive.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware attributed in the report to nation-state activity; described as using a Microsoft OneDrive account for data exfiltration to blend in with legitimate cloud behavior.
A multi-component toolset used post-infection by APT29 to establish and maintain footholds, including loader, downloader, and backdoor capabilities with remote command execution.
CloudDuke (aka MiniDionis) is a backdoor malware used by APT29/Cozy Bear for espionage and persistent access.
CloudDuke (aka MiniDionis) is a backdoor malware used by APT29/Cozy Bear for espionage and persistent access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.