SeaDuke, also known as SeaDaddy and SeaDesk, is a Python-based espionage backdoor used by APT29, also known as Cozy Bear and The Dukes, a threat group attributed to Russia’s Foreign Intelligence Service. It has Windows and Linux variants and has been used selectively against high-value government, diplomatic, policy, and research targets in the United States and Europe. SeaDuke appeared in compromised networks in October 2014 and was subsequently identified in the Democratic National Committee intrusion.
SeaDuke is a configurable framework that supports system-information collection, command execution, file uploads and downloads, configuration updates, and self-removal. Its operators can deploy additional modules to extract Microsoft Exchange email using compromised credentials, perform Kerberos pass-the-ticket attacks through PowerShell-based Mimikatz, archive sensitive data, exfiltrate information through legitimate cloud services, and securely delete files. Windows persistence mechanisms include PowerShell, registry-based autostart, and startup shortcuts.
SeaDuke has been deployed as a follow-on payload on systems already infected with CozyCar, also called CozyDuke, using encoded PowerShell scripts to download and execute it. Windows samples package Python code with PyInstaller and employ multiple layers of obfuscation, including UPX packing, Base64 encoding, and compression. Command-and-control communications use HTTP or HTTPS, Base64 encoding, and RC4 and AES encryption, with compromised web servers serving as infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT29 has used encoded PowerShell scripts uploaded to CozyCar installations to download and install SeaDuke.
Seaduke (detected by Symantec as Trojan.Seaduke) is a low-profile information-stealing Trojan which appears to be reserved for attacks against a small number of high-value targets.
Seaduke (detected by Symantec as Trojan.Seaduke) is a low-profile information-stealing Trojan which appears to be reserved for attacks against a small number of high-value targets.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Other alternatives include using a universal scripting language, such as Python, to write their codebase. This was seen previously by the Chafer threat group that wrote one of their payloads in Python.
APT29 has used encoded PowerShell scripts uploaded to CozyCar installations to download and install SeaDuke. APT29 also used PowerShell to create new tasks on remote machines, identify configuration settings, evade defenses, exfiltrate data, and to execute other commands. | AppleSeed has the ability to execute its payload via PowerShell... APT19 used PowerShell commands to execute payloads... APT28 downloads and executes PowerShell scripts and performs PowerShell commands... Start-Process / Invoke-Command / System.Management.Automation
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
they must rely on packaging them using a utility such as PyInstaller.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
ADVSTORESHELL C2 traffic is encrypted, then encoded with Base64 encoding. APT19 HTTP malware variant used Base64 to encode communications to the C2 server. APT33 has used base64 to encode command and control traffic.
50 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Seaduke is a specific malware family, often associated with advanced persistent threat (APT) operations. It is known for its use in targeted cyber espionage campaigns.
A Python-based cross-platform backdoor for Windows and Linux that executes C2 commands, transfers files, and runs additional code.
SeaDuke is a backdoor malware used by APT29/Cozy Bear for espionage operations.
SeaDuke is a backdoor malware used by APT29/Cozy Bear for espionage operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.