Skip to content

Malware

FatDuke

According to ESET Research, FatDuke is the current flagship backdoor of APT29 and is only deployed on the most interesting machines.

FatDuke is a Windows malware family operated by APT29.

Background

ESET Research characterizes FatDuke as APT29's leading backdoor at the time, reserved for the highest-value machines. While it is normally delivered by the MiniDuke backdoor, ESET has also observed operators planting it via lateral movement utilities like PsExec. The actors frequently repack the malware to slip past detection; the newest sample ESET observed was compiled on May 24, 2019, and they watched the operators attempt to reassert control of a host repeatedly within a few days, using a different sample each time. The packer inflates the binaries with substantial extra code—though the functional code should be under 1MB, ESET saw one sample reach 13MB, which inspired the name FatDuke.


Source: Malpedia (Fraunhofer FKIE).