SeaDuke

S0053

Malware.View on attack.mitre.org

About this malware

SeaDuke is malware that was used by APT29 from 2014 to 2015. It was used primarily as a secondary backdoor for victims that were already compromised with CozyCar.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1027.002
Software Packing

SeaDuke has been packed with the UPX packer.

T1059.001
PowerShell

SeaDuke uses a module to execute Mimikatz with PowerShell to perform Pass the Ticket.

T1059.003
Windows Command Shell

SeaDuke is capable of executing commands.

T1070.004
File Deletion

SeaDuke can securely delete files, including deleting itself from the victim.

T1071.001
Web Protocols

SeaDuke uses HTTP and HTTPS for C2.

T1078
Valid Accounts

Some SeaDuke samples have a module to extract email from Microsoft Exchange servers using compromised credentials.

T1105
Ingress Tool Transfer

SeaDuke is capable of uploading and downloading files.

T1114.002
Remote Email Collection

Some SeaDuke samples have a module to extract email from Microsoft Exchange servers using compromised credentials.

T1132.001
Standard Encoding

SeaDuke C2 traffic is base64-encoded.

T1546.003
Windows Management Instrumentation Event Subscription

SeaDuke uses an event filter in WMI code to execute a previously dropped executable shortly after system startup.

T1547.001
Registry Run Keys / Startup Folder

SeaDuke is capable of persisting via the Registry Run key or a .lnk file stored in the Startup directory.

T1547.009
Shortcut Modification

SeaDuke is capable of persisting via a .lnk file stored in the Startup directory.

T1550.003
Pass the Ticket

Some SeaDuke samples have a module to use pass the ticket with Kerberos for authentication.

T1560.002
Archive via Library

SeaDuke compressed data with zlib prior to sending it over C2.

T1573.001
Symmetric Cryptography

SeaDuke C2 traffic has been encrypted with RC4 and AES.

Groups that use it1

Campaigns0

None recorded.

References1

  1. F-Secure The Dukes Open source
    F-Secure Labs. (2015, September 17). The Dukes: 7 years of Russian cyberespionage. Retrieved December 10, 2015.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.