Netskope Threat Labs

Dukes

ATP Sandbox Adv. HeuristicsAV

Dukes refers to detections associated with the Dukes (a.k.a. Cozy Bear and APT29), a Russian state sponsored threat group known for espionage against governments, think tanks, and technology providers. The group deploys staged malware families such as CozyCar and CozyDuke and conducted the 2020 SolarWinds supply chain compromise.

First seen
July 2023
Last seen
October 2026
Alert Name
Gen:Variant.Dukes.2
Win64.Trojan.Dukes