Trojan-Dropper:W32/CosmicDuke steals information from an infected system using keylogging, screen captures and stealing file and clipboard data. Harvested data is forwarded to a remote server via FTP.
Based on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the detected program or file, or ask you for a desired action.
Find the latest advice in our Community Knowledge Base.
See the manual for your F-Secure product on the Help Center.
Submit a file or URL for further analysis.
The CosmicDuke trojan-dropper appears to be spread in 'bait' image, document and PDF files, which contain an exploit or a buried Windows executable program. Once the bait file is opened, the exploit or program is launched and begins to harvest data from the infected machine.
In addition to its information-stealing activities, CosmicDuke is notable for sharing code with MiniDuke, a malware known to have been used to attack various NATO and European government agencies in February 2013.
For more information, see Labs Weblog post:CosmicDuke: Cosmu With a Twist of MiniDuke or download the whitepaper.