logo

F-Secure_Dukes_Whitepaper.pdf

ID: 1c76aca6-787f-457b-8230-407ced910fad

STIX ID: report--1c76aca6-787f-457b-8230-407ced910fad

Threat Score

90/100

Uploaded: 2026-08-11

Published Date: 2020-03-26

Last Modified Date: 2020-03-26

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** The F-Secure whitepaper documents seven years (2008–2015) of operations by the Dukes (APT29), cataloguing numerous malware toolsets (MiniDuke, CosmicDuke, OnionDuke, CozyDuke, CloudDuke, SeaDuke, HammerDuke, PinchDuke, GeminiDuke), infection vectors (spear-phishing, malicious Tor exit, trojanized torrents), TTPs, detailed IOCs (SHA1 hashes, domains, IPs), campaign timelines and an assessment attributing the activity to Russian state-sponsored cyberespionage.