CosmicDuke is a Windows espionage malware family within the Duke toolset associated with APT29, also known as Cozy Bear or The Dukes. It is commonly characterized as a hybrid backdoor and information stealer designed for long-term intelligence collection from compromised hosts. Reporting has linked it to the broader Duke ecosystem alongside MiniDuke, CozyDuke, SeaDuke, GeminiDuke, PinchDuke, OnionDuke, HammerDuke, and CloudDuke, and some samples and reporting connect it to the internal project name Nemesis Gemina.
CosmicDuke focuses on harvesting sensitive user and system data. Documented capabilities include theft of credentials from web browsers, email clients, instant messaging applications, and wireless network profiles; keylogging; periodic screenshot capture; clipboard collection; collection of files from local hard drives and removable media based on predefined extension or keyword lists; and general host information gathering. It also supports command-and-control communications for follow-on operator tasking, making it useful both as a surveillance implant and as a remotely managed backdoor.
Persistence mechanisms observed for CosmicDuke include abuse of Windows Scheduled Tasks and Windows services. Reported variants have created scheduled tasks and installed services masquerading as legitimate software components to survive reboots and maintain execution. Some analyzed samples also performed security-product checks before continuing, indicating basic defense-evasion logic.
CosmicDuke has been described as using custom packing and in some cases a modified RC4 implementation containing a programming flaw. It has also been observed unpacking code in memory and launching additional components, reflecting a modular architecture with loaders and optional plugins around a primary information-stealing core.
The malware has been associated with cyber-espionage activity attributed to APT29 and has been reported targeting high-value sectors including government, finance, healthcare, energy, technology, academia, media, pharmaceuticals, and think tanks. Victim geography reported for related activity includes the United States, the United Kingdom, Germany, and Japan. Overall, CosmicDuke is best understood as a mature Windows intelligence-collection platform used in targeted intrusions by the Duke espionage ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CosmicDuke attempts to exploit privilege escalation vulnerabilities CVE-2010-0232 or CVE-2010-4398.
CosmicDuke attempts to exploit privilege escalation vulnerabilities CVE-2010-0232 or CVE-2010-4398.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It has a range of malware tools at its disposal, known as the Dukes, including Cozyduke, Miniduke and Cosmicduke.
It has a range of malware tools at its disposal, known as the Dukes, including Cozyduke, Miniduke and Cosmicduke.
It has a range of malware tools at its disposal, known as the Dukes, including Cozyduke, Miniduke and Cosmicduke.
In 2014, we reported other malware used by “The Dukes”, named CosmicDuke.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
APT28 has exploited CVE-2014-4076, CVE-2015-2387, CVE-2015-1701, CVE-2017-0263, and CVE-2022-38028 to escalate privileges.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
This sample is a component of the CosmicDuke malware, which is obtaining the desktop details of victim systems by calling the RegQueryValueExW, RegOpenKeyExW...
This CosmicDuke backdoor loader initially verifies any security product running in the victim system before executing the CosmicDuke malware activity by calling CreateToolhelp32Snapshot, Process32Next, and Process32First.
Additionally, this malware collects the computer name, keyboard layout details, what drivers are available on the victim system, etc.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
AppleSeed can find and collect data from removable media devices. APT28 backdoor may collect the entire contents of an inserted USB device. Aria-body has the ability to collect data from USB devices. BADNEWS copies files with certain extensions from USB devices to a predefined directory.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
MITRE ATT&CK Tactics and Techniques (Based on our analysis): Command and Control(TA0011) T1071: Application Layer Protocol
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
57 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
CosmicDuke is a modular espionage malware used by APT29 for long-term cyber-espionage campaigns, featuring advanced persistence and stealth capabilities.
Mentioned as malware that has used clipboard hijacking techniques.
An information-stealing malware family with optional persistence and privilege-escalation modules.
CosmicDuke is a backdoor malware used by the APT29/Cozy Bear threat actor for espionage and data exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.