MiniDuke is a Windows cyberespionage toolset comprising downloader, loader, and backdoor components, associated with APT29, also known as the Dukes or Cozy Bear, a threat group attributed to Russia’s Foreign Intelligence Service. Publicly documented in 2013, MiniDuke remained in operational use in 2019. It has been deployed against government and diplomatic organizations, including entities in Eastern Europe and former Soviet states. In Operation Ghost, it served as a second-stage backdoor in intrusions affecting European foreign ministries and a European Union country’s embassy in Washington, DC. Operators have also installed MiniDuke on systems already compromised with CozyDuke.
MiniDuke’s assembly-written backdoor provides extensive remote control through commands for file upload and download, file and directory manipulation, process creation and termination, drive enumeration, and host profiling. It can execute processes using supplied domain-user credentials. Its communications use HTTP requests, while some variants support named-pipe relaying through another compromised machine with Internet access. A documented 2019 variant supports exfiltration through HTTP PUT, HTTP POST, and named pipes, including encrypted data disguised as JPEG image content.
The toolset incorporates resilient command-and-control discovery. MiniDuke can obtain server locations through Twitter and use Google Search as a fallback when the primary discovery channel fails. It can also algorithmically generate Twitter URLs. Evasion techniques vary by component and include compressed payload containers, encrypted strings, control-flow flattening, hashed API resolution, and custom data encryption. Some samples derive a system-specific configuration encryption key using a modified SHA-1 routine and host information. MiniDuke is distinct from CosmicDuke, which combines MiniDuke backdoor functionality with the Cosmu information-stealing family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
MiniDuke ... Dynamic Resolution: Domain Generation Algorithms ... Fallback Channels ... Web Service: Dead Drop Resolver.
In parallel, the Duke group was also installing separate malware onto these networks, namely Backdoor.Miniduke and the more elusive Trojan.Seaduke.
In parallel, the Duke group was also installing separate malware onto these networks, namely Backdoor.Miniduke and the more elusive Trojan.Seaduke.
In February 2014 we observed the Miniduke threat actor using the same backdoor on their hacked servers, although using a much stronger password.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Byte = 0x33 – create a new process in the security context of the credentials received from the C2 server
the backdoor has added a lot of obfuscation that consists of control-flow flattening (every function is split in a switch/case, and a lot of computation that is useless for the main execution flow is added)
The encrypted buffer is added to a fake JPEG image (note the file signature in the network traffic) and transmitted to the C2 server without raising any suspicion
Byte = 0x33 – create a new process in the security context of the credentials received from the C2 server
the backdoor also performs a “cleaning” operation by freeing the memory in order to hide possible IOCs that could be extracted from it
The malware retrieves the NetBIOS name of the local computer and the user name by calling the GetComputerNameA and GetUserNameA functions
Discovery T1057 Process Discovery The Dukes can list running processes.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
Command and Control T1071 Standard Application Layer Protocol The Dukes are using HTTP and HTTPS protocols to communicate with the C&C server.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
APT41 used the Steam community page as a fallback mechanism for C2. Crutch has used a hardcoded GitHub repository as a fallback channel. MiniDuke uses Google Search to identify C2 servers if its primary C2 method via Twitter is not working.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A staged toolset comprising downloader, backdoor, and loader components.
MiniDuke is a backdoor malware used by the APT29/Cozy Bear threat actor for cyber espionage operations.
MiniDuke is a backdoor malware used by the APT29/Cozy Bear threat actor for cyber espionage operations.
MiniDuke is discussed as the malware sample implementing a modified SHA1 hashing algorithm used to derive a per-system encryption key for its configuration. The hashed buffer includes the current computer name concatenated with network interface descriptions, and the resulting 160-bit value is used by the malware for configuration encryption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.