Open Threat Intel Archive
OTIA
Indicators
ATT&CK
Threat actors
MITRE ATT&CK intrusion sets
Malware & tools
Software families & tooling
Techniques
Tactics & techniques
Reports
Sources
Developers
JSON API
Free CORS-enabled endpoints
MCP server
Model Context Protocol access
Source code
This project on GitHub
Loading the archive…
Open Threat Intel Archive
← Malware & tools
S0052
malware
OnionDuke
OnionDuke is malware that was used by APT29 from 2013 to 2015.
Platforms
Windows
MITRE ATT&CK ↗
Linked entities · 6
uses
T1499
Endpoint Denial of Service
uses
T1102.003
One-Way Communication
uses
T1071.001
Web Protocols
uses
T1140
Deobfuscate/Decode Files or Infor…
uses
T1003
OS Credential Dumping
uses by
G0016
APT29