Also known as: DarkUniverse, SIG27, Strider, USB Thief, PlexingEagle, SinSono, tracked as, field, malicious actors, APT groups, hackers, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, White Tur, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code
ItaDuke is a long‑standing espionage operation attributed by Kaspersky to the DarkUniverse group that operated between 2009 and 2017. The actor exploits known PDF vulnerabilities (CVE‑2013‑0640/641) to drop malware into victim systems and then leverages compromised Twitter accounts as low–profile command‑and‑control channels, allowing it to bypass traditional detection mechanisms. Beyond initial delivery, the group develops custom droppers, backdoors, and packers that obfuscate malicious code. It routinely exploits legitimate software packages and commodity tools, including PowerShell scripts, Microsoft Windows utilities such as rundll32.exe and msbuild.exe, and cloud‑native components like Amazon AMIs, Google Cloud images, Azure images, and Docker containers. By embedding malware into these infrastructure artifacts it achieves persistence even when the underlying host is rebuilt. ItaDuke also conducts credential compromise across email, social media, and cloud storage services and executes internal spearphishing against legitimate accounts to facilitate lateral movement within victim organisations. Financial objectives are pursued through ransomware deployments, BEC campaigns, pig‑butchering operations, and cryptocurrency theft, thereby amplifying the threat’s operational impact. The actor’s tactics cover the full lifecycle of a sophisticated attack: initial access via public‑facing exploits; execution using command‑line interpreters and autostart mechanisms; persistence through boot‑scripts, scheduled jobs, container backdoors, and cloud image injection; credential theft; data collection and exfiltration by leveraging cloud storage services; and post‑exploitation cleanup to evade detection.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
ItaDuke is a nation‑state actor that has operated since 2013, using CVE‑2013‑0640/641 PDF exploits and compromised Twitter accounts for command‑and‑control to deliver malware into target systems ranging from media to defense and financial institutions. The group also leverages legitimate cloud services and backdoored container images to achieve persistence and exfiltration while conducting large‑scale financial theft via ransomware, BEC, pig‑butchering, and crypto schemes.
Goals & Targeting
ItaDuke is primarily driven by strategic espionage objectives for a nation‑state, targeting sectors that grant access to sensitive political, military, and commercial information such as defence, media, telecommunications, and aerospace. The attacker also pursues financial gains through ransomware, pig‑butchering, and crypto‑related theft, thereby providing both intelligence and monetary benefits to its sponsors. Its targeting profile shows a predilection for high‑value organizations in North America and Asia (US, Canada, UK, JP, KR), with an opportunistic approach that expands into non‑profit and educational institutions when advantageous.
Enhanced Description
Key Capabilities
No campaigns linked yet.
No observed data linked yet.
40
Techniques
41
Tools
0
Campaigns
39
IOCs
0
Observed Data
13
Tactics