DoublePulsar
- First seen
- 2017-04-13 00:00:00
- Malware type
- backdoor, rootkit
- Profile updated
- 2026-07-07 13:00:03
Targeted industries: government-and-public-sector healthcare-and-pharmaceutical
Context
DoublePulsar is a backdoor tool used in conjunction with the EternalBlue exploit to enable remote code execution on targeted systems. It primarily serves to facilitate further malware distribution and maintain persistence on infected hosts.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Doublepulsar_Auto (yara-rule)
Reports & references
- ESET — Backdoordiplomacy Upgrading Quarian Turian (report)
- labs.nettitude.com — A Quick Analysis Of The Latest Shadow Brokers Dump (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Doublepulsar (report)
- Broadcom/Symantec — Buckeye Windows Zero Day Exploit (report)
- github.com — Doublepulsar C2 Traffic Decryptor (report)