logo

"Forkmeiamfamous": Seaduke, latest weapon in the Duke armory

ID: f176c2c5-7aef-4c87-8644-4442a2c7aeca

STIX ID: report--f176c2c5-7aef-4c87-8644-4442a2c7aeca

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2015-07-22

Last Modified Date: 2015-07-22

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec describes Seaduke, a Python-based, highly configurable information‑stealing Trojan deployed by the Duke APT against select high-value government, diplomatic, and research targets; Seaduke is typically delivered via Cozyduke (encoded PowerShell tasks), communicates with layered Base64/RC4/AES over HTTP(S) to hundreds of compromised web servers, and supports payloads for email exfiltration, Kerberos pass‑the‑ticket impersonation, archiving, and secure deletion, reflecting a sophisticated long‑running espionage campaign.