Last seven days
- First activity
- Aug 11, 2026
- Last activity
- Aug 11, 2026
- Feed role
- C2
- Host form
- 2 IP / 0 hostnames
CosmicDuke is an information-stealing malware family associated with The Dukes/APT29 and also referenced under the aliases TinyBaron, BotgenStudios, and NemesisGemina.
Profile source: Mallory opens in a new tabCosmicDuke
CosmicDuke is an information-stealing malware family associated with The Dukes/APT29 and also referenced under the aliases TinyBaron, BotgenStudios, and NemesisGemina. The toolset is built around a primary information stealer with optional components. Reported capabilities include acting as a keylogger, taking periodic screenshots and exfiltrating them, copying and exfiltrating clipboard contents every 30 seconds, stealing user files, exporting information, and collecting credentials. It steals files from local hard drives, removable media, and network shared drives when file extensions and keywords match a predefined list. It collects credentials, including passwords, from web browsers, instant messaging applications, email clients, WLAN keys, and LSA secrets. For persistence, CosmicDuke has used Windows services typically named "javamtsup" and scheduled tasks typically named "Watchmon Service." It has also been reported to attempt privilege escalation via CVE-2010-0232 or CVE-2010-4398. For command and control, it can use HTTP or HTTPS to hard-coded C2 servers. For exfiltration, it sends collected files over FTP or WebDAV and can use exfiltration servers configured separately from its C2 servers. The content also notes that APT29 used CosmicDuke in a 2014 campaign to steal sensitive information from victims worldwide.
C2 tracking
Derp observations, rolling seven-day window
Samples
22b16ae7007f123a302637202864361d87211b973082dcfb05887d84030b85a2 368f11354fdfc4197aa262e13f0f0c1d5c004a19fc5c1e508add3c4ab371d9b7 5ebbe0286b639c99458301fd43fbda4c9846f1e0a042123eea01e882ff556069 aedd0c32afe0cab411e766707350be3394e4cb3b2d3ab33504afa1137d73b6ed ce9b2e40600a90b6c76943bc31f4e644ee0b4542439ff2d21bc5ac2f9de98a3e fb8c2d6c9ea9a610239dcab21e83a72a2c76f0fc6ba6547c8711eb6e15ed63f4 Reported operators
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.