Skip to content

Malware

tDiscoverer

aka HAMMERTOSS · HammerDuke

F-Secure described tDiscoverer (also known as HammerDuke) as interesting because it is written in .NET, and even more so because of its occasional use of Twitter as a C&C communication channel.

tDiscoverer, also known as HAMMERTOSS, HammerDuke, is a Windows malware family operated by APT29.

Background

According to F-Secure, tDiscoverer (also called HammerDuke) is notable for being a .NET implant, and especially for sometimes routing its C&C traffic through Twitter. Certain HammerDuke samples simply pull commands from a hardcoded C&C address, while others first derive a Twitter handle from the current date using a custom algorithm. When that handle exists, the malware looks for tweets from it linking to images that conceal commands the toolset then runs.


Source: Malpedia (Fraunhofer FKIE).