PowerDuke: Widespread Post-Election Spear Phishing Campaigns Targeting Think Tanks and NGOs
ID: 030a5407-179d-4984-b73b-d1caa0db57dd
STIX ID: report--030a5407-179d-4984-b73b-d1caa0db57dd
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2016-12-31
Last Modified Date: 2016-12-31
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Volexity observed five coordinated post‑election spear‑phishing waves attributed to The Dukes (APT29/Cozy Bear) targeting think tanks, NGOs and universities. Attack vectors included malicious Word macros, password‑protected ZIPs containing LNK dropper files and executables, use of steganography/ADS to hide PowerDuke backdoor components, anti‑VM checks, and multiple C2 servers and domains; the report provides file hashes, filenames, domains and IPs for detection and response.
