Skip to content

S0054 CloudDuke

CloudDuke is malware that was used by APT29 in 2015. 1 2

Item Value
ID S0054
Associated Names
Version 1.1
Created 31 May 2017
Last Modified 30 March 2020
Navigation Layer View In ATT&CK® Navigator

Techniques Used

Domain ID Name Use
enterprise T1071 Application Layer Protocol -
enterprise T1071.001 Web Protocols One variant of CloudDuke uses HTTP and HTTPS for C2.1
enterprise T1105 Ingress Tool Transfer CloudDuke downloads and executes additional malware from either a Web address or a Microsoft OneDrive account.1
enterprise T1102 Web Service -
enterprise T1102.002 Bidirectional Communication One variant of CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data with its operators.1

Groups That Use This Software

ID Name References
G0016 APT29 1


Back to top