ATT&CKSoftwareCosmicDuke

CosmicDuke

S0050

Malware.View on attack.mitre.org

About this malware

CosmicDuke is malware that was used by APT29 from 2010 to 2015.

Techniques used19

Procedure examples19

TechniqueProcedure example
T1003.002
Security Account Manager

CosmicDuke collects Windows account hashes.

T1003.004
LSA Secrets

CosmicDuke collects LSA secrets.

T1005
Data from Local System

CosmicDuke steals user files from local hard drives with file extensions that match a predefined list.

T1020
Automated Exfiltration

CosmicDuke exfiltrates collected files automatically over FTP to remote servers.

T1025
Data from Removable Media

CosmicDuke steals user files from removable media with file extensions and keywords that match a predefined list.

T1039
Data from Network Shared Drive

CosmicDuke steals user files from network shared drives with file extensions and keywords that match a predefined list.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

CosmicDuke exfiltrates collected files over FTP or WebDAV. Exfiltration servers can be separately configured from C2 servers.

T1053.005
Scheduled Task

CosmicDuke uses scheduled tasks typically named "Watchmon Service" for persistence.

T1056.001
Keylogging

CosmicDuke uses a keylogger.

T1068
Exploitation for Privilege Escalation

CosmicDuke attempts to exploit privilege escalation vulnerabilities CVE-2010-0232 or CVE-2010-4398.

T1071.001
Web Protocols

CosmicDuke can use HTTP or HTTPS for command and control to hard-coded C2 servers.

T1083
File and Directory Discovery

CosmicDuke searches attached and mounted drives for file extensions and keywords that match a predefined list.

T1113
Screen Capture

CosmicDuke takes periodic screenshots and exfiltrates them.

T1114.001
Local Email Collection

CosmicDuke searches for Microsoft Outlook data files with extensions .pst and .ost for collection and exfiltration.

T1115
Clipboard Data

CosmicDuke copies and exfiltrates the clipboard contents every 30 seconds.

View all 19 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. F-Secure The Dukes Open source
    F-Secure Labs. (2015, September 17). The Dukes: 7 years of Russian cyberespionage. Retrieved December 10, 2015.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.