Netskope Threat Labs

MiniDuke

ATP Sandbox Adv. HeuristicsAV

MiniDuke is a malware toolset that APT29 used from 2010 to 2015. The toolset consists of multiple downloader and backdoor components, and its loader also worked with CosmicDuke and PinchDuke components across the wider family of tools.

First seen
February 2022
Last seen
September 2026

9 techniques across 3 tactics.

TA0005 Stealth

  • T1027Obfuscated Files or Information

TA0007 Discovery

  • T1082System Information Discovery
  • T1083File and Directory Discovery

TA0011 Command and Control

Alert Name
Gen:Variant.MiniDuke.1
Gen:Variant.MiniDuke.2
Win32.Backdoor.MiniDuke
Win32.Dropper.MiniDuke