RegDuke

MITRE
Tipo Malware:
Other
Prima attivita:
Unknown
Ultima attivita:
Unknown
Dettagli:

[RegDuke](https://attack.mitre.org/software/S0511) is a first stage implant written in .NET and used by [APT29](https://attack.mitre.org/groups/G0016) since at least 2017. [RegDuke](https://attack.mitre.org/software/S0511) has been used to control a compromised machine when control of other implants on the machine was lost.(Citation: ESET Dukes October 2019)

Tecniche Associate (9)
ID ATT&CK Tattiche
T1027 Obfuscated Files or Information -
T1027.003 Steganography -
T1027.011 Fileless Storage -
T1059.001 PowerShell -
T1102.002 Bidirectional Communication -
T1105 Ingress Tool Transfer -
T1112 Modify Registry -
T1140 Deobfuscate/Decode Files or Information -
T1546.003 Windows Management Instrumentation Event Subscription -
Usato da Attori (1)
Metadata
ID: 183
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00