RegDuke

MITRE ATT&CK: S0511 View on attack.mitre.org

Aliases: RegDuke

First seen
2017-01-01 00:00:00
Malware type
backdoor, rat, loader
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:20:51

Targeted industries: government-and-public-sector technology-and-telecommunications energy-and-utilities healthcare-and-pharmaceutical

Targeted regions: country_code:us country_code:gb country_code:ca

Context

RegDuke is a first stage implant written in .NET and used by APT29 since at least 2017. RegDuke has been used to control a compromised machine when control of other implants on the machine was lost.

Detection coverage

  • 448 Sigma rules

Malware & tools used

  • Ingress Tool Transfer (attack-pattern)
  • Steganography (attack-pattern)
  • Windows Management Instrumentation Event Subscription (attack-pattern)
  • PowerShell (attack-pattern)
  • Modify Registry (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Fileless Storage (attack-pattern)
  • Bidirectional Communication (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)

Used by threat actors

  • Operation Ghost (campaign)
  • APT29 (threat-actor)

Reports & references

  • ESET — Eset Operation Ghost Dukes (report)
  • MITRE ATT&CK — S0511 (report)

External references