Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ItaDuke

Also known as: DarkUniverse, SIG27, Strider, USB Thief, PlexingEagle, SinSono, tracked as, field, malicious actors, APT groups, hackers, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, White Tur, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code

Description

ItaDuke is a long‑standing espionage operation attributed by Kaspersky to the DarkUniverse group that operated between 2009 and 2017. The actor exploits known PDF vulnerabilities (CVE‑2013‑0640/641) to drop malware into victim systems and then leverages compromised Twitter accounts as low–profile command‑and‑control channels, allowing it to bypass traditional detection mechanisms. Beyond initial delivery, the group develops custom droppers, backdoors, and packers that obfuscate malicious code. It routinely exploits legitimate software packages and commodity tools, including PowerShell scripts, Microsoft Windows utilities such as rundll32.exe and msbuild.exe, and cloud‑native components like Amazon AMIs, Google Cloud images, Azure images, and Docker containers. By embedding malware into these infrastructure artifacts it achieves persistence even when the underlying host is rebuilt. ItaDuke also conducts credential compromise across email, social media, and cloud storage services and executes internal spearphishing against legitimate accounts to facilitate lateral movement within victim organisations. Financial objectives are pursued through ransomware deployments, BEC campaigns, pig‑butchering operations, and cryptocurrency theft, thereby amplifying the threat’s operational impact. The actor’s tactics cover the full lifecycle of a sophisticated attack: initial access via public‑facing exploits; execution using command‑line interpreters and autostart mechanisms; persistence through boot‑scripts, scheduled jobs, container backdoors, and cloud image injection; credential theft; data collection and exfiltration by leveraging cloud storage services; and post‑exploitation cleanup to evade detection.

Goals & Targeting

Targeted Sectors

Media
Defense
Government
Financial services
Non profit
Pharmaceutical
Telecommunications
Aviation
Energy
Manufacturing
Education
Information technology

Targeted Countries / Regions

CN
US
JP
GB
KR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

ItaDuke is a nation‑state actor that has operated since 2013, using CVE‑2013‑0640/641 PDF exploits and compromised Twitter accounts for command‑and‑control to deliver malware into target systems ranging from media to defense and financial institutions. The group also leverages legitimate cloud services and backdoored container images to achieve persistence and exfiltration while conducting large‑scale financial theft via ransomware, BEC, pig‑butchering, and crypto schemes.

Goals & Targeting

ItaDuke is primarily driven by strategic espionage objectives for a nation‑state, targeting sectors that grant access to sensitive political, military, and commercial information such as defence, media, telecommunications, and aerospace. The attacker also pursues financial gains through ransomware, pig‑butchering, and crypto‑related theft, thereby providing both intelligence and monetary benefits to its sponsors. Its targeting profile shows a predilection for high‑value organizations in North America and Asia (US, Canada, UK, JP, KR), with an opportunistic approach that expands into non‑profit and educational institutions when advantageous.

Enhanced Description

Key Capabilities

  • Compromised Twitter accounts for C2
  • PDF Vulnerability exploitation (CVE-2013-0640/641)
  • Backdoor implant via in‑house malware
  • Droppers and packers for obfuscation
  • Container and cloud image backdooring
  • Credential harvesting via password stores
  • Internal spearphishing of legitimate accounts
  • Financial theft tactics including ransomware, BEC and crypto
  • Automated automated collection & exfiltration through cloud services

ATT&CK Techniques

Exfiltration
1 technique
Initial Access
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: services
  2. attack.mitre.org — Cited by web research for: Process Hollowing
  3. securelist.com — Cited by web research for: Dark

Intel Summary

40

Techniques

41

Tools

0

Campaigns

39

IOCs

0

Observed Data

13

Tactics

Tags

APT
espionage
government
nation-state

Details

Type
Nation-State
Resource Level
Unknown
Primary Motivation
Espionage
Confidence
70%
Added
Jul 21, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.