Netskope Threat Labs

SeaDuke

ATP Sandbox Adv. HeuristicsAV

SeaDuke is malware associated with the Russian APT29 group that provided cross platform backdoor capabilities on compromised systems. Its Python based design ran on Windows and Linux, and its operators used it quietly in espionage campaigns, including intrusions into political organizations. The family's modest footprint and flexible configuration made it a useful second stage tool in long running operations.

First seen
March 2022
Last seen
October 2026
Seaduke

15 techniques across 7 tactics.

TA0002 Execution

TA0003 Persistence

TA0004 Privilege Escalation

  • T1546Event Triggered Execution
    • T1546.003Windows Management Instrumentation Event Subscription

TA0005 Stealth

TA0008 Lateral Movement

TA0009 Collection

TA0011 Command and Control

Alert Name
Binary.Trojan.SeaDuke
DeepScan:Generic.Seaduke.1.FFFFFFFE
Dump:Generic.Seaduke.1.FFFFFFFE
Generic.Seaduke.1.002A6613
Generic.Seaduke.1.002D6C8D
Generic.Seaduke.1.007C06D0
Generic.Seaduke.1.00F1CACC
Generic.Seaduke.1.00FDBE0F
Generic.Seaduke.1.010B4525
Generic.Seaduke.1.01162D90