PolyglotDuke

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[PolyglotDuke](https://attack.mitre.org/software/S0518) is a downloader that has been used by [APT29](https://attack.mitre.org/groups/G0016) since at least 2013. [PolyglotDuke](https://attack.mitre.org/software/S0518) has been used to drop [MiniDuke](https://attack.mitre.org/software/S0051).(Citation: ESET Dukes October 2019)

Associated Techniques (10)
ID ATT&CK Tactics
T1027 Obfuscated Files or Information -
T1027.003 Steganography -
T1027.011 Fileless Storage -
T1071.001 Web Protocols -
T1102.001 Dead Drop Resolver -
T1105 Ingress Tool Transfer -
T1106 Native API -
T1112 Modify Registry -
T1140 Deobfuscate/Decode Files or Information -
T1218.011 Rundll32 -
Used by Actors (1)
Metadata
ID: 158
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00