PinchDuke is an information-stealing malware family associated with APT29, also known as The Dukes, a Russian cyberespionage threat actor. It is described as a toolset comprising several loaders and a core credential-stealing trojan used on compromised Windows systems. PinchDuke is designed to harvest credentials from infected hosts, including browser-stored and application-stored secrets, and its credential theft functionality has been linked to code derived from the Pinch, or LdPinch, credential stealer. Reported targets for credential collection include the WinInet credential cache, LDAP-associated credentials, and credentials tied to applications and services such as Microsoft Outlook, The Bat!, Yahoo!, Mail.ru, Passport.Net, and Google Talk. Beyond credential theft, PinchDuke can gather system configuration information, search for files created within specified timeframes, collect user files matching predefined extension lists, and transfer stolen data from the victim over HTTP or HTTPS to command-and-control infrastructure. The malware has been used as part of broader Dukes espionage operations focused on intelligence collection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group’s malware and campaigns include PinchDuke, GeminiDuke, CosmicDuke, MiniDuke, CozyDuke, OnionDuke, SeaDuke, HammerDuke and CloudDuke.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims... BlackByte used tools such as Cobalt Strike and Mimikatz to dump credentials from victim systems... Storm-0501 has used the SecretsDump module within Impacket can perform credential dumping to obtain account and password information.
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Evilnum can collect email credentials from victims... Malteiro has obtained credentials from mail clients via NirSoft MailPassView... MgBot includes modules for stealing stored credentials from Outlook and Foxmail email client software... PLEAD has the ability to steal saved passwords from Microsoft Outlook.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A toolset with multiple loaders and a core information-stealing trojan, with overlap observed with CosmicDuke loaders.
PinchDuke is a backdoor malware used by APT29/Cozy Bear for espionage and data exfiltration.
PinchDuke is a backdoor malware used by APT29/Cozy Bear for espionage and data exfiltration.
Credential-stealing malware targeting credentials from browsers and other applications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.