logo

PowerDuke: Widespread Post-Election Spear Phishing Campaigns Targeting Think Tanks and NGOs

ID: fa0a8a73-f804-5270-bc7f-d70df5ac39ab

STIX ID: report--fa0a8a73-f804-5270-bc7f-d70df5ac39ab

Feed Name: Volexity Blog

Threat Score
90/100

Date Published: 2016-11-09

Date Updated: 2026-05-01

...
...

Volexity observed five coordinated post-election spear-phishing waves attributed to The Dukes (APT29/Cozy Bear) targeting U.S. think tanks, NGOs and universities; attackers used malicious Word/Excel attachments, LNK/PowerShell droppers and password-protected ZIPs to deploy the PowerDuke backdoor. PowerDuke employs anti-VM checks, steganography (PNG alternate data streams), persistence via rundll32 and a broad command set for reconnaissance and control; the report provides file hashes, domains, IPs and ASN information for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.