DoublePulsar

First seen
2017-04-13 00:00:00
Malware type
backdoor, rootkit
Profile updated
2026-07-07 13:00:03

Targeted industries: government-and-public-sector healthcare-and-pharmaceutical

Context

DoublePulsar is a backdoor tool used in conjunction with the EternalBlue exploit to enable remote code execution on targeted systems. It primarily serves to facilitate further malware distribution and maintain persistence on infected hosts.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Doublepulsar_Auto (yara-rule)

Reports & references

  • ESET — Backdoordiplomacy Upgrading Quarian Turian (report)
  • labs.nettitude.com — A Quick Analysis Of The Latest Shadow Brokers Dump (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Doublepulsar (report)
  • Broadcom/Symantec — Buckeye Windows Zero Day Exploit (report)
  • github.com — Doublepulsar C2 Traffic Decryptor (report)

External references