LiteDuke is a Windows backdoor associated with the Dukes espionage cluster, commonly linked to APT29/Cozy Bear. It was used as a third-stage implant around 2014–2015 and appears designed for long-term covert access on high-value targets. The malware is delivered through a staged loader chain in which encrypted payload components are unpacked and decrypted in memory before the main implant is executed via a DLL export mechanism. LiteDuke employs multiple layers of encryption and obfuscation to hinder analysis and conceal its components.
Once installed, LiteDuke establishes persistence on Windows by creating an autorun shortcut that launches the loader at user logon. It maintains a local encrypted SQL database used to store configuration data and operational objects, and it supports modular functionality through database-backed modules or plugins. The implant performs host reconnaissance, including enumeration of the current account name, installed software, operating system and hardware details, and network adapter information. It can also derive browser-specific HTTP user-agent values and retrieve proxy settings from supported browsers to blend command-and-control traffic with the victim environment.
LiteDuke includes defensive-awareness and evasion behavior, such as checking for the presence of Kaspersky software and using layered decryption and packing. Its command set supports file operations, process control, named-pipe interaction, configuration updates, database manipulation, and broader system profiling. It has also been observed securely deleting files by overwriting data before removal. Overall, LiteDuke is a feature-rich espionage backdoor built for stealthy post-compromise operations in targeted intrusions attributed to the Dukes/APT29.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The droppers for PolyglotDuke and LiteDuke embed encrypted payloads.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The Dukes encrypts PolyglotDuke and LiteDuke payloads with custom algorithms. They also rely on known obfuscation techniques such as opaque predicates and control flow flattening to obfuscate RegDuke, MiniDuke and FatDuke.
This DLL allocates a segment of virtual memory and decodes content from a .bmp resource. The decoded memory is a block of four executable files.
Writes a file named NTUSER.DAT here... The .lnk file calls rundll32.exe, passing the .DAT file and the LoadRegistry DLL, forcing the application to run at login.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
Terminate a process (via CreateToolhelp32Snapshot and Process32First/Next).
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
Retrieve current directory... Retrieve drive and disk space information... Retrieve entries in objects table.
List installed programs by enumerating the “DisplayName” values in the “\CurrentVersion\Uninstall” key.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Their toolkit includes ... HammerDuke, LiteDuke, MagicWeb, meek...
Backdoor that can enumerate the account name on a targeted system.
Discovers browser proxy configuration on infected systems.
Enterprise New Software: ... LiteDuke
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.