Movatterモバイル変換


[0]ホーム

URL:


  1. Home
  2. Software
  3. SeaDuke

SeaDuke

SeaDuke is malware that was used byAPT29 from 2014 to 2015. It was used primarily as a secondary backdoor for victims that were already compromised withCozyCar.[1]

ID: S0053
Associated Software: SeaDaddy, SeaDesk
Type: MALWARE
Platforms: Windows
Version: 1.1
Created: 31 May 2017
Last Modified: 25 April 2025
Enterprise Layer
downloadview

Techniques Used

DomainIDNameUse
EnterpriseT1071.001Application Layer Protocol:Web Protocols

SeaDuke uses HTTP and HTTPS for C2.[1]

EnterpriseT1560.002Archive Collected Data:Archive via Library

SeaDuke compressed data with zlib prior to sending it over C2.[2]

EnterpriseT1547.001Boot or Logon Autostart Execution:Registry Run Keys / Startup Folder

SeaDuke is capable of persisting via the Registry Run key or a .lnk file stored in the Startup directory.[3]

.009Boot or Logon Autostart Execution:Shortcut Modification

SeaDuke is capable of persisting via a .lnk file stored in the Startup directory.[3]

EnterpriseT1059.001Command and Scripting Interpreter:PowerShell

SeaDuke uses a module to execute Mimikatz with PowerShell to performPass the Ticket.[4]

.003Command and Scripting Interpreter:Windows Command Shell

SeaDuke is capable of executing commands.[3]

EnterpriseT1132.001Data Encoding:Standard Encoding

SeaDuke C2 traffic is base64-encoded.[3]

EnterpriseT1114.002Email Collection:Remote Email Collection

SomeSeaDuke samples have a module to extract email from Microsoft Exchange servers using compromised credentials.[4]

EnterpriseT1573.001Encrypted Channel:Symmetric Cryptography

SeaDuke C2 traffic has been encrypted with RC4 and AES.[2][3]

EnterpriseT1546.003Event Triggered Execution:Windows Management Instrumentation Event Subscription

SeaDuke uses an event filter in WMI code to execute a previously dropped executable shortly after system startup.[5]

EnterpriseT1070.004Indicator Removal:File Deletion

SeaDuke can securely delete files, including deleting itself from the victim.[4]

EnterpriseT1105Ingress Tool Transfer

SeaDuke is capable of uploading and downloading files.[3]

EnterpriseT1027.002Obfuscated Files or Information:Software Packing

SeaDuke has been packed with the UPX packer.[3]

EnterpriseT1550.003Use Alternate Authentication Material:Pass the Ticket

SomeSeaDuke samples have a module to use pass the ticket with Kerberos for authentication.[4]

EnterpriseT1078Valid Accounts

SomeSeaDuke samples have a module to extract email from Microsoft Exchange servers using compromised credentials.[4]

Groups That Use This Software

IDNameReferences
G0016APT29

[1][6][4]

References

×

[8]ページ先頭

©2009-2026 Movatter.jp