CosmicDuke is a Windows information-stealing malware family with backdoor functionality associated with The Dukes, also known as APT29 or Cozy Bear. It combines the MiniDuke backdoor with the Cosmu information-stealing family and forms part of a toolkit used in cyberespionage operations against government, policy, and research organizations. Its distribution mechanisms include spearphishing, malicious advertising, and exploit kits.
CosmicDuke harvests passwords and other credentials from web browsers, email clients, and instant-messaging applications, as well as wireless network keys. It records keystrokes, captures periodic screenshots, and copies and exfiltrates clipboard contents every 30 seconds. It also steals files from local disks and removable media using predefined file-extension and keyword criteria. Its backdoor functionality supports command execution, system-information gathering, drive and filesystem enumeration, and communication with attacker-controlled infrastructure. Observed communications include HTTP POST requests carrying host information and FTP uploads of harvested data.
CosmicDuke establishes persistence through scheduled tasks and automatically starting Windows services. It attempts local privilege escalation through CVE-2010-0232 or CVE-2010-4398. Analyzed variants use custom packing, in-memory payload decryption, anti-debugging measures, execution delays, and security-software checks to hinder analysis and detection. They also masquerade as legitimate software, including a Google Chrome updater and Microsoft components. The family contains a custom RC4 implementation with a programming error.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CosmicDuke attempts to exploit privilege escalation vulnerabilities CVE-2010-0232 or CVE-2010-4398.
Carberp has exploited CVE-2010-4398 for privilege escalation. CosmicDuke attempts to exploit privilege escalation vulnerabilities CVE-2010-0232 or CVE-2010-4398. FIN6 tools targeted CVE-2010-4398 to access kernel-level privileges. | CosmicDuke attempts to exploit privilege escalation vulnerabilities CVE-2010-0232 or CVE-2010-4398.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CosmicDuke ... Automated Exfiltration ... Clipboard Data ... Credentials from Password Stores ... Input Capture: Keylogging.
It has a range of malware tools at its disposal, known as the Dukes, including Cozyduke, Miniduke and Cosmicduke.
It has a range of malware tools at its disposal, known as the Dukes, including Cozyduke, Miniduke and Cosmicduke.
In 2014, we reported other malware used by “The Dukes”, named CosmicDuke.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
This sample is a component of the CosmicDuke malware, which is obtaining the desktop details of victim systems by calling the RegQueryValueExW, RegOpenKeyExW.
This malware takes a snapshot of the running process by calling CreateToolhelp32Snapshot.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
61 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
CosmicDuke is a modular espionage malware used by APT29 for long-term cyber-espionage campaigns, featuring advanced persistence and stealth capabilities.
Mentioned as malware that has used clipboard hijacking techniques.
An information-stealing malware family with optional persistence and privilege-escalation modules.
CosmicDuke is a backdoor malware used by the APT29/Cozy Bear threat actor for espionage and data exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.