PDA

View Full Version : The Dukes: 7 years of Russian Cyber-espionage



RandomGuy
05-25-2017, 12:32 PM
Whitepaper by F-Secure.

Good open-source background material outlining Russian state capabilities. (see link to paper below)


Today we release a new whitepaper on an APT group commonly referred to as “the Dukes”. We believe that the Dukes are a well-resourced, highly dedicated, and organized cyber-espionage group that has been working for the Russian government since at least 2008 to collect intelligence in support of foreign and security policy decision-making.

The Dukes (sometimes also referred to as APT29) are known to employ a wide arsenal of malware toolsets including MiniDuke, CosmicDuke, OnionDuke, CozyDuke, SeaDuke, CloudDuke (aka MiniDionis), and HammerDuke (aka HAMMERTOSS [PDF]).

Despite the extensive technical research by us and others into many of the toolsets of the Dukes, we felt that we were still missing crucial parts of the story. Meanwhile, others had envisioned how the story might look, but had concluded that “it is difficult to lead the defense against that which one is not aware of or does not comprehend.” (Maldre, 2015)

With this in mind, we recently set out on a journey back through all of our previous research on the Dukes looking for clues and threads that we might have missed or whose importance we might not have understood at the time. Through this process, we were able to uncover clues pointing to the existence of two previously unidentified Duke malware toolsets, PinchDuke and GeminiDuke.

Blog here:
https://labsblog.f-secure.com/2015/09/17/the-dukes-7-years-of-russian-cyber-espionage/

pdf:
https://www.f-secure.com/documents/996508/1030745/dukes_whitepaper.pdf

rjv
05-25-2017, 12:37 PM
but cyber espionage has been around for a while now and it is not uncommon among the major powers. china, russia and the US have all done it to one another.

RandomGuy
05-25-2017, 12:44 PM
but cyber espionage has been around for a while now and it is not uncommon among the major powers. china, russia and the US have all done it to one another.


They have indeed. It is worth noting though, how those capabilities are used.

This particular one was one I found by following a link, helpfully provided by the NYT.


WASHINGTON — When Special Agent Adrian Hawkins of the Federal Bureau of Investigation called the Democratic National Committee in September 2015 to pass along some troubling news about its computer network, he was transferred, naturally, to the help desk.

His message was brief, if alarming. At least one computer system belonging to the D.N.C. had been compromised by hackers federal investigators had named “the Dukes,” a cyberespionage team linked to the Russian government.

The F.B.I. knew it well: The bureau had spent the last few years trying to kick the Dukes out of the unclassified email systems of the White House, the State Department and even the Joint Chiefs of Staff, one of the government’s best-protected networks.

Yared Tamene, the tech-support contractor at the D.N.C. who fielded the call, was no expert in cyberattacks. His first moves were to check Google for “the Dukes” and conduct a cursory search of the D.N.C. computer system logs to look for hints of such a cyberintrusion. By his own account, he did not look too hard even after Special Agent Hawkins called back repeatedly over the next several weeks — in part because he wasn’t certain the caller was a real F.B.I. agent and not an impostor.

https://www.nytimes.com/2016/12/13/us/politics/russia-hack-election-dnc.html

boutons_deux
05-25-2017, 12:53 PM
They have indeed. It is worth noting though, how those capabilities are used.

This particular one was one I found by following a link, helpfully provided by the NYT.


https://www.nytimes.com/2016/12/13/us/politics/russia-hack-election-dnc.html

As this Russian shit comes out, the Dems should be repeatedly calling Trash ILLEGITIMATE (which would really drive him crazy, er, crazier)

Chucho
05-25-2017, 04:27 PM
As this Russian shit comes out, the Dems should be repeatedly calling Trash ILLEGITIMATE (which would really drive him crazy, er, crazier)


Kinda like lack of evidence driving you...I dunno, more delusional and indoctrinated with the Fascist Left. Either way, you're a hot fucking mess.

hater
05-25-2017, 05:28 PM
"Everyone spies on each other." - Barack Hussein Obomba

RandomGuy
06-02-2017, 11:40 AM
"Everyone spies on each other." - Barack Hussein Obomba

Sure.

Is Germany spying on us the same as Russia spying on us?