Last seven days
- First activity
- Jul 22, 2026
- Last activity
- Jul 22, 2026
- Feed role
- C2
- Host form
- 2 IP / 0 hostnames
CosmicDuke is an information-stealing malware family associated with The Dukes/APT29 and also referenced under the aliases TinyBaron, BotgenStudios, and NemesisGemina.
Profile source: Mallory opens in a new tabCosmicDuke
CosmicDuke is an information-stealing malware family associated with The Dukes/APT29 and also referenced under the aliases TinyBaron, BotgenStudios, and NemesisGemina. The toolset is built around a primary information stealer with optional components. Reported capabilities include acting as a keylogger, taking periodic screenshots and exfiltrating them, copying and exfiltrating clipboard contents every 30 seconds, stealing user files, exporting information, and collecting credentials. It steals files from local hard drives, removable media, and network shared drives when file extensions and keywords match a predefined list. It collects credentials, including passwords, from web browsers, instant messaging applications, email clients, WLAN keys, and LSA secrets. For persistence, CosmicDuke has used Windows services typically named "javamtsup" and scheduled tasks typically named "Watchmon Service." It has also been reported to attempt privilege escalation via CVE-2010-0232 or CVE-2010-4398. For command and control, it can use HTTP or HTTPS to hard-coded C2 servers. For exfiltration, it sends collected files over FTP or WebDAV and can use exfiltration servers configured separately from its C2 servers. The content also notes that APT29 used CosmicDuke in a 2014 campaign to steal sensitive information from victims worldwide.
C2 tracking
Derp observations, rolling seven-day window
Samples
29632b240c950557943ca6d203f4337d59c9a97763cd8aef9c3a54d6fd07dbfb 2c14b7366f12eaed351f8a84fe7b65366310ae8318fa7ebbf14de20eccabfa09 4eafbc4c4eeb32e63f228f3bed1207c2af3e16397d15ab7e45edf4cc9d69dd8a 8efb2f32958263ab22ff08de5b7b79bc945de55444ae29c79a6694260ffe46da c473d1fa3b38ddb26af057cc2d61b171d78f64d4562bac2129fde512eee0b862 Reported operators
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.