Skip to content

CosmicDuke

CosmicDuke is a Windows espionage malware family within the Duke toolset associated with APT29, also known as Cozy Bear or The Dukes.

Profile source: Mallory opens in a new tab

CosmicDuke

Family profile

CosmicDuke is a Windows espionage malware family within the Duke toolset associated with APT29, also known as Cozy Bear or The Dukes. It is commonly characterized as a hybrid backdoor and information stealer designed for long-term intelligence collection from compromised hosts. Reporting has linked it to the broader Duke ecosystem alongside MiniDuke, CozyDuke, SeaDuke, GeminiDuke, PinchDuke, OnionDuke, HammerDuke, and CloudDuke, and some samples and reporting connect it to the internal project name Nemesis Gemina.

CosmicDuke focuses on harvesting sensitive user and system data. Documented capabilities include theft of credentials from web browsers, email clients, instant messaging applications, and wireless network profiles; keylogging; periodic screenshot capture; clipboard collection; collection of files from local hard drives and removable media based on predefined extension or keyword lists; and general host information gathering. It also supports command-and-control communications for follow-on operator tasking, making it useful both as a surveillance implant and as a remotely managed backdoor.

Persistence mechanisms observed for CosmicDuke include abuse of Windows Scheduled Tasks and Windows services. Reported variants have created scheduled tasks and installed services masquerading as legitimate software components to survive reboots and maintain execution. Some analyzed samples also performed security-product checks before continuing, indicating basic defense-evasion logic.

CosmicDuke has been described as using custom packing and in some cases a modified RC4 implementation containing a programming flaw. It has also been observed unpacking code in memory and launching additional components, reflecting a modular architecture with loaders and optional plugins around a primary information-stealing core.

The malware has been associated with cyber-espionage activity attributed to APT29 and has been reported targeting high-value sectors including government, finance, healthcare, energy, technology, academia, media, pharmaceuticals, and think tanks. Victim geography reported for related activity includes the United States, the United Kingdom, Germany, and Japan. Overall, CosmicDuke is best understood as a mature Windows intelligence-collection platform used in targeted intrusions by the Duke espionage ecosystem.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 5, 2026
Last activity
Sep 5, 2026
Feed role
C2
Host form
2 IP / 0 hostnames

Leading locations

  • SE1
  • US1

Leading providers

  • Glesys AB1
  • Interserver, Inc1

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

Reported operators

Threat actors

4 named in public reporting
Office Monkeys

It has a range of malware tools at its disposal, known as the Dukes, including Cozyduke, Miniduke and Cosmicduke.

EuroAPT

It has a range of malware tools at its disposal, known as the Dukes, including Cozyduke, Miniduke and Cosmicduke.

APT29

It has a range of malware tools at its disposal, known as the Dukes, including Cozyduke, Miniduke and Cosmicduke.

Turla

In 2014, we reported other malware used by “The Dukes”, named CosmicDuke.

Exploited software

Vulnerabilities linked to CosmicDuke

2 CVEs

MITRE ATT&CK

CosmicDuke in ATT&CK

35 distinct techniques

Reporting

Research mentioning CosmicDuke

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.