Skip to content

Malware

PinchDuke

According to F-Secure, the PinchDuke information stealer gathers system configuration information, steals user credentials, and collects user files from the compromised host transferring these via HTT

PinchDuke is a Windows malware family operated by APT29.

Background

F-Secure reports that the PinchDuke information stealer collects system configuration details, harvests user credentials, and gathers user files from the infected machine, sending them over HTTP(S) to a C&C server. F-Secure assesses that PinchDuke's credential-theft component is built on the source code of the Pinch credential stealer (also known as LdPinch), which originated in the early 2000s and was later circulated freely on underground forums.


Source: Malpedia (Fraunhofer FKIE).