Skip to content
Malware family

CosmicDuke

CosmicDuke is an information-stealing malware family associated with The Dukes/APT29 and also referenced under the aliases TinyBaron, BotgenStudios, and NemesisGemina.

Profile source: Mallory opens in a new tab

CosmicDuke

Family profile

CosmicDuke is an information-stealing malware family associated with The Dukes/APT29 and also referenced under the aliases TinyBaron, BotgenStudios, and NemesisGemina. The toolset is built around a primary information stealer with optional components. Reported capabilities include acting as a keylogger, taking periodic screenshots and exfiltrating them, copying and exfiltrating clipboard contents every 30 seconds, stealing user files, exporting information, and collecting credentials. It steals files from local hard drives, removable media, and network shared drives when file extensions and keywords match a predefined list. It collects credentials, including passwords, from web browsers, instant messaging applications, email clients, WLAN keys, and LSA secrets. For persistence, CosmicDuke has used Windows services typically named "javamtsup" and scheduled tasks typically named "Watchmon Service." It has also been reported to attempt privilege escalation via CVE-2010-0232 or CVE-2010-4398. For command and control, it can use HTTP or HTTPS to hard-coded C2 servers. For exfiltration, it sends collected files over FTP or WebDAV and can use exfiltration servers configured separately from its C2 servers. The content also notes that APT29 used CosmicDuke in a 2014 campaign to steal sensitive information from victims worldwide.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 22, 2026
Last activity
Jul 22, 2026
Feed role
C2
Host form
2 IP / 0 hostnames

Leading locations

  • SE1
  • US1

Leading providers

  • Glesys AB1
  • Interserver, Inc1

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
APT29

CosmicDuke : The CosmicDuke toolset is built around a primary information stealer, enhanced by various optional components.

Turla

In 2014, we reported other malware used by β€œThe Dukes”, named CosmicDuke.

Exploited software

Vulnerabilities linked to CosmicDuke

2 CVEs

MITRE ATT&CK

CosmicDuke in ATT&CK

24 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.