logo

PowerDuke: Widespread Post-Election Spear Phishing Campaigns Targeting Think Tanks and NGOs

ID: 030a5407-179d-4984-b73b-d1caa0db57dd

STIX ID: report--030a5407-179d-4984-b73b-d1caa0db57dd

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2016-12-31

Last Modified Date: 2016-12-31

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Volexity observed five coordinated post‑election spear‑phishing waves attributed to The Dukes (APT29/Cozy Bear) targeting think tanks, NGOs and universities. Attack vectors included malicious Word macros, password‑protected ZIPs containing LNK dropper files and executables, use of steganography/ADS to hide PowerDuke backdoor components, anti‑VM checks, and multiple C2 servers and domains; the report provides file hashes, filenames, domains and IPs for detection and response.