RegDuke — Malware Profile

RegDuke is a first stage implant written in .NET and used by APT29 since at least 2017. RegDuke has been used to control a compromised machine when control of other implants on the machine was lost.

MITRE ATT&CK techniques (9)

Attributed threat actors

Read the full analysis on IntelFusions