Currently viewing ATT&CK v8.2 which was live between October 27, 2020 and April 28, 2021. Learn more about the versioning system or see the live site.

CloudDuke

CloudDuke is malware that was used by APT29 in 2015. [1] [2]

ID: S0054
Associated Software: MiniDionis, CloudLook
Type: MALWARE
Platforms: Windows
Version: 1.1
Created: 31 May 2017
Last Modified: 30 March 2020

Techniques Used

Domain ID Name Use
Enterprise T1071 .001 Application Layer Protocol: Web Protocols

One variant of CloudDuke uses HTTP and HTTPS for C2.[1]

Enterprise T1105 Ingress Tool Transfer

CloudDuke downloads and executes additional malware from either a Web address or a Microsoft OneDrive account.[1]

Enterprise T1102 .002 Web Service: Bidirectional Communication

One variant of CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data with its operators.[1]

Groups That Use This Software

ID Name References
G0016 APT29

[1]

References