RegDuke — Malware Profile
RegDuke is a first stage implant written in .NET and used by APT29 since at least 2017. RegDuke has been used to control a compromised machine when control of other implants on the machine was lost.
MITRE ATT&CK techniques (9)
- T1027 Obfuscated Files or Information
- T1027.003 Steganography
- T1027.011 Fileless Storage
- T1059.001 PowerShell
- T1102.002 Bidirectional Communication
- T1105 Ingress Tool Transfer
- T1112 Modify Registry
- T1140 Deobfuscate/Decode Files or Information
- T1546.003 Windows Management Instrumentation Event Subscription