F-Secure_Dukes_Whitepaper.pdf
ID: 1c76aca6-787f-457b-8230-407ced910fad
STIX ID: report--1c76aca6-787f-457b-8230-407ced910fad
Threat Score
90/100
Uploaded: 2026-08-11
Published Date: 2020-03-26
Last Modified Date: 2020-03-26
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** The F-Secure whitepaper documents seven years (2008–2015) of operations by the Dukes (APT29), cataloguing numerous malware toolsets (MiniDuke, CosmicDuke, OnionDuke, CozyDuke, CloudDuke, SeaDuke, HammerDuke, PinchDuke, GeminiDuke), infection vectors (spear-phishing, malicious Tor exit, trojanized torrents), TTPs, detailed IOCs (SHA1 hashes, domains, IPs), campaign timelines and an assessment attributing the activity to Russian state-sponsored cyberespionage.
