Also known as: TinyBaron, BotgenStudios, NemesisGemina
Executive Summary
CosmicDuke is a Windows RAT used by APT29 (The Dukes) from 2010‑15 to conduct espionage via remote command and control. It delivers backdoor capabilities and exfiltrates sensitive data over HTTP/HTTPS, making it a persistent threat for targeted organizations.
Enhanced Description
CosmicDuke is a Windows‐based remote access trojan that operated as part of the APT29 threat actor’s toolset from 2010 to 2015, according to F‑Secure reports on The Dukes. The malware functions as a typical espionage RAT: it establishes command and control connectivity over HTTP/HTTPS, downloads additional payloads, collects system information, and exfiltrates data from compromised hosts. Common capabilities include file system reconnaissance, credential harvesting and keylogging, making it suitable for long‑term intelligence gathering. CosmicDuke’s code base is modular; once installed it spawns a background service that persists across reboots and can communicate with multiple command servers. It is often referenced under the aliases TinyBaron, BotgenStudios, and NemesisGemina, reflecting its use in various espionage campaigns. Overall, CosmicDuke demonstrates classic APT29 techniques: stealthy persistence, outbound communication over standard web protocols, and payload delivery for lateral movement or data theft.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the baseline description is moderate; it is derived from publicly cited F‑Secure analysis but lacks direct code‑level observation. Detailed technical behavior (e.g., specific exfiltration vectors or encryption) remains speculative and should be verified by internal forensic labs.
CosmicDuke is malware that was used by APT29 from 2010 to 2015. (Citation: F-Secure The Dukes)