Trojan-Dropper:W32/CosmicDuke

Threat description

Details

CATEGORYMalware
TYPETrojan-Dropper

Summary

Trojan-Dropper:W32/CosmicDuke steals information from an infected system using keylogging, screen captures and stealing file and clipboard data. Harvested data is forwarded to a remote server via FTP.



Removal

Automatic action

Depending on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the suspect file, or ask you for a desired action.

More scanning & removal options

More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.

Technical Details

The CosmicDuke trojan-dropper appears to be spread in 'bait' image, document and PDF files, which contain an exploit or a buried Windows executable program. Once the bait file is opened, the exploit or program is launched and begins to harvest data from the infected machine.

In addition to its information-stealing activities, CosmicDuke is notable for sharing code with MiniDuke, a malware known to have been used to attack various NATO and European government agencies in February 2013.

For more information, see Labs Weblog post:CosmicDuke: Cosmu With a Twist of MiniDuke or download the whitepaper.

Submit a Sample

Suspect a file or URL was wrongly detected?
Send it to our Labs for further analysis

Submit a Sample

Scan & clean your PC

F-Secure Online Scanner will scan and clean your PC in just a few minutes for free

More Info