"Forkmeiamfamous": Seaduke, latest weapon in the Duke armory
ID: f176c2c5-7aef-4c87-8644-4442a2c7aeca
STIX ID: report--f176c2c5-7aef-4c87-8644-4442a2c7aeca
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2015-07-22
Last Modified Date: 2015-07-22
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec describes Seaduke, a Python-based, highly configurable information‑stealing Trojan deployed by the Duke APT against select high-value government, diplomatic, and research targets; Seaduke is typically delivered via Cozyduke (encoded PowerShell tasks), communicates with layered Base64/RC4/AES over HTTP(S) to hundreds of compromised web servers, and supports payloads for email exfiltration, Kerberos pass‑the‑ticket impersonation, archiving, and secure deletion, reflecting a sophisticated long‑running espionage campaign.
