Description
Dukes refers to detections associated with the Dukes (a.k.a. Cozy Bear and APT29), a Russian state sponsored threat group known for espionage against governments, think tanks, and technology providers. The group deploys staged malware families such as CozyCar and CozyDuke and conducted the 2020 SolarWinds supply chain compromise.
Stats
- First seen
- July 2023
- Last seen
- October 2026
Alert name variants
| Alert Name |
|---|
| Gen:Variant.Dukes.2 |
| Win64.Trojan.Dukes |