HomeSecurityMeet The Dukes - a powerful APT group backed by Russia

Meet The Dukes - a powerful APT group backed by Russia

Security researchers at F-Secure have exposed a major new APT group that they claim has been operating for the past seven years, gathering intelligence from government and related organizations in the US, Europe and Asia.The activity associated with APT29, or “The Dukes” as the group has been dubbed by the Finnish security firm, dates back to 2008, with the first known attacks against the West coming a year later.
It uses nine different malware variants – some of which, like MiniDuke, were already known to researchers, but two, including CloudDuke, were recently revealed in this report. Furthermore, it details a determined group with very good resources and a particular penchant for targeting Western organizations.

Meet The Dukes - a powerful APT group backed by Russia
F-Secure explained the group’s somewhat unusual MO:
“These campaigns use a smash-and-grab approach involving a quick but noisy ‘break-in’ followed by the rapid collection and purging of as much data as possible. If the target is discovered to be of value, The Dukes will quickly change their toolkit and move towards more covert tactics based on persistent compromise and long-term intelligence gathering.”
In addition to these raids, the group has apparently claimed responsibility for smaller, more targeted campaigns whose goals and timelines “appear to align with known foreign interests and the security policy of the Russian Federation during this period.”
The group is poised to respond to the new investigation, modifying tools to remain hidden, but in other cases using tools that have already been made public, F-Secure said.
This confidence suggests that it has no fear of repercussions – as it further strengthens the case for “The Dukes” as a state-sponsored group.
The most common method of infection for The Dukes is a phishing email. However, some OnionDuke variants have been spread via a malicious Tor node designed to inject trojans into legitimate applications on-the-fly, the report revealed.
Despite its apparent sophistication and state support, the group appears to have only exploited one zero-day vulnerability so far – CVE-2013-0640 (MiniDuke).
While the researchers conclude that the group has a “primary mission of gathering intelligence to support foreign policy and security policy decision-making” for the Russian Federation, they are unable to clarify whether it is a group within a government agency or a purely commercial organization.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS