S0054 CloudDuke
CloudDuke is malware that was used by APT29 in 2015. 1 2
| Item | Value |
|---|---|
| ID | S0054 |
| Associated Names | |
| Type | MALWARE |
| Version | 1.1 |
| Created | 31 May 2017 |
| Last Modified | 30 March 2020 |
| Navigation Layer | View In ATT&CK® Navigator |
Techniques Used
| Domain | ID | Name | Use |
|---|---|---|---|
| enterprise | T1071 | Application Layer Protocol | - |
| enterprise | T1071.001 | Web Protocols | One variant of CloudDuke uses HTTP and HTTPS for C2.1 |
| enterprise | T1105 | Ingress Tool Transfer | CloudDuke downloads and executes additional malware from either a Web address or a Microsoft OneDrive account.1 |
| enterprise | T1102 | Web Service | - |
| enterprise | T1102.002 | Bidirectional Communication | One variant of CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data with its operators.1 |
Groups That Use This Software
| ID | Name | References |
|---|---|---|
| G0016 | APT29 | 1 |