Last seven days
- First activity
- Sep 5, 2026
- Last activity
- Sep 5, 2026
- Feed role
- C2
- Host form
- 2 IP / 0 hostnames
CosmicDuke is a Windows espionage malware family within the Duke toolset associated with APT29, also known as Cozy Bear or The Dukes.
Profile source: Mallory opens in a new tabCosmicDuke
CosmicDuke is a Windows espionage malware family within the Duke toolset associated with APT29, also known as Cozy Bear or The Dukes. It is commonly characterized as a hybrid backdoor and information stealer designed for long-term intelligence collection from compromised hosts. Reporting has linked it to the broader Duke ecosystem alongside MiniDuke, CozyDuke, SeaDuke, GeminiDuke, PinchDuke, OnionDuke, HammerDuke, and CloudDuke, and some samples and reporting connect it to the internal project name Nemesis Gemina.
CosmicDuke focuses on harvesting sensitive user and system data. Documented capabilities include theft of credentials from web browsers, email clients, instant messaging applications, and wireless network profiles; keylogging; periodic screenshot capture; clipboard collection; collection of files from local hard drives and removable media based on predefined extension or keyword lists; and general host information gathering. It also supports command-and-control communications for follow-on operator tasking, making it useful both as a surveillance implant and as a remotely managed backdoor.
Persistence mechanisms observed for CosmicDuke include abuse of Windows Scheduled Tasks and Windows services. Reported variants have created scheduled tasks and installed services masquerading as legitimate software components to survive reboots and maintain execution. Some analyzed samples also performed security-product checks before continuing, indicating basic defense-evasion logic.
CosmicDuke has been described as using custom packing and in some cases a modified RC4 implementation containing a programming flaw. It has also been observed unpacking code in memory and launching additional components, reflecting a modular architecture with loaders and optional plugins around a primary information-stealing core.
The malware has been associated with cyber-espionage activity attributed to APT29 and has been reported targeting high-value sectors including government, finance, healthcare, energy, technology, academia, media, pharmaceuticals, and think tanks. Victim geography reported for related activity includes the United States, the United Kingdom, Germany, and Japan. Overall, CosmicDuke is best understood as a mature Windows intelligence-collection platform used in targeted intrusions by the Duke espionage ecosystem.
C2 tracking
Derp observations, rolling seven-day window
Samples
12c4e49a9d6a78884be70248f7d841aa136d93e82ef0045fd0441eda762a3036 9c61fe2d5e3dc8bc84b6b23651c5976c99ae78eae48cc651ffafd7c80f833db6 d83a3677613921ffc82205c81c88ef66f66c3239599f2a235f244f217e6ce823 eb7bcb6a2b99f2f13b1bb4631f824532d66e7e1aaed775ca27f9fb284fef8652 eed615d2209c572d0aadebf1b92747690d151f0e22e8680c821ac7bc014863d3 Reported operators
It has a range of malware tools at its disposal, known as the Dukes, including Cozyduke, Miniduke and Cosmicduke.
It has a range of malware tools at its disposal, known as the Dukes, including Cozyduke, Miniduke and Cosmicduke.
It has a range of malware tools at its disposal, known as the Dukes, including Cozyduke, Miniduke and Cosmicduke.
In 2014, we reported other malware used by “The Dukes”, named CosmicDuke.
Exploited software
MITRE ATT&CK
Reporting
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.