Threat intelligence
- Suspected origin
- Russia
- Targeted countries
- Russia
- TLP
- WHITE
(F-Secure) The Dukes are a well-resourced, highly dedicated and organized cyberespionage group that we believe has been working for the Russian Federation since at least 2008 to collect intelligence in support of foreign and security policy decision-making.
The Dukes primarily target Western governments and related organizations, such as government ministries and agencies, political think tanks, and governmental subcontractors. Their targets have also included the governments of members of the Commonwealth of Independent States; Asian, African, and Middle Eastern governments; organizations associated with Chechen extremism; and Russian speakers engaged in the illicit trade of controlled substances and drugs.
The Dukes are known to employ a vast arsenal of malware toolsets, which we identify as MiniDuke, CosmicDuke, OnionDuke, CozyDuke, CloudDuke, SeaDuke, HammerDuke, PinchDuke, and GeminiDuke. In recent years, the Dukes have engaged in apparently biannual large-scale spear-phishing campaigns against hundreds or even thousands of recipients associated with governmental institutions and affiliated organizations.
These campaigns utilize a smash-and-grab approach involving a fast but noisy break-in followed by the rapid collection and exfiltration of as much data as possible. If the compromised target is discovered to be of value, the Dukes will quickly switch the toolset used and move to using stealthier tactics focused on persistent compromise and long-term intelligence gathering.
In addition to these large-scale campaigns, the Dukes continuously and concurrently engage in smaller, much more targeted campaigns, utilizing different toolsets. These targeted campaigns have been going on for at least 7 years. The targets and timing of these campaigns appear to align with the known foreign and security policy interests of the Russian Federation at those times.
Also known as
APT 29APT29ATK 7Blue Dev 5Blue KitsuneBlueBravoCloaked UrsaCloudLookCozy BearCozyDukeCraneflyDark HaloEarth KoshcheiG0016Grizzly SteppeGroup 100Iron HemlockIron RitualITG11Midnight BlizzardMinidionisNobeliumNobleBaronSilverFishSolar PhoenixSolarStormStellarParticleTEMP.MonkeysThe DukesUNC2452UNC3524Yttrium
Vulnerabilities exploited
Tooling and malware
BoomBoxCloudDukeCobalt StrikeCosmicDukeCozyCarEnvyScoutFatDukeFoggyWebGeminiDukeGoldFinderGoldMaxHAMMERTOSSLiteDukeMiniDukeNativeZoneOnionDukePinchDukePolyglotDukePOSHSPYPowerDukeQUIETEXITRaindropRegDukereGeorgSeaDukeSibotSoreFangSUNBURSTSUNSPOTTEARDROPTrailBlazerVaporRageWellMailWellMessAADInternalsAdFindBloodHoundImpacketipconfigmeek
MITRE ATT&CK techniques
T1005 Data from Local SystemT1105 Ingress Tool TransferT1568 Dynamic ResolutionT1573 Encrypted ChannelT1665 Hide InfrastructureT1528 Steal Application Access TokenT1621 Multi-Factor Authentication Request GenerationT1649 Steal or Forge Authentication CertificatesT1047 Windows Management InstrumentationT1203 Exploitation for Client ExecutionT1651 Cloud Administration CommandT1190 Exploit Public-Facing ApplicationT1199 Trusted RelationshipT1037 Boot or Logon Initialization ScriptsT1133 External Remote ServicesT1068 Exploitation for Privilege EscalationT1078 Valid Accounts
Coverage 8
threat-intel
Google has identified three distinct groups of Russian cyber-spies – UNC6293, UNC7005, and UNC5976 – that are aggressively targeting individuals in academia, defense, government, and think tanks across Europe and the US.…

threat-intel
Threat actors are increasingly leveraging trusted collaboration platforms – like Microsoft Teams and Slack – to conduct sophisticated identity phishing attacks. Instead of relying solely on traditional email phishing, at…

threat-intel
This week’s cybersecurity recap highlighted a concerning trend of AI-powered exploit generation, alongside a series of high-impact security incidents. A vulnerability in Coldcard hardware wallets led to an $88.6 million…

threat-intel
Russian state-sponsored hackers, linked to the Midnight Blizzard group (part of APT29), are compromising hotel Wi-Fi networks worldwide to steal traveler login credentials and install espionage malware. The campaign uses…

threat-intel
A Russian state-sponsored APT group, Storm-2945 (linked to Midnight Blizzard/APT29), is leveraging compromised public Wi-Fi gateway networks to steal Microsoft 365 credentials of traveling employees. The campaign involve…
threat-intel
A sophisticated campaign, dubbed CaptiveCrunch, is leveraging hijacked hotel Wi-Fi networks to deliver surveillance malware – specifically CornFlake, a remote access trojan – to unsuspecting guests. The attacks are orche…

threat-intel
The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa…
threat-intel
This report details a tactic employed by threat actors, primarily Cloaked Ursa (APT29), to compromise organizations by impersonating IT departments within Microsoft Teams. The attackers leverage trusted communication cha…
