ATT&CKSoftwareGeminiDuke

GeminiDuke

S0049

Malware.View on attack.mitre.org

About this malware

GeminiDuke is malware that was used by APT29 from 2009 to 2012.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1007
System Service Discovery

GeminiDuke collects information on programs and services on the victim that are configured to automatically run at startup.

T1016
System Network Configuration Discovery

GeminiDuke collects information on network settings and Internet proxy settings from the victim.

T1057
Process Discovery

GeminiDuke collects information on running processes and environment variables from the victim.

T1071.001
Web Protocols

GeminiDuke uses HTTP and HTTPS for command and control.

T1083
File and Directory Discovery

GeminiDuke collects information from the victim, including installed drivers, programs previously executed by users, programs and services configured to automatically run at startup, files and folders present in any user's home folder, files and folders present in any user's My Documents, programs installed to the Program Files folder, and recently accessed files, folders, and programs.

T1087.001
Local Account

GeminiDuke collects information on local user accounts from the victim.

Groups that use it1

Campaigns0

None recorded.

References1

  1. F-Secure The Dukes Open source
    F-Secure Labs. (2015, September 17). The Dukes: 7 years of Russian cyberespionage. Retrieved December 10, 2015.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.